Skip to content

XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution

Critical severity GitHub Reviewed Published Apr 10, 2024 in xwiki/xwiki-commons • Updated Jan 9, 2025

No open alerts for this advisory

Give feedback on Dependabot alerts