peter bassill · operator
$ cve CVE-2023-26475 JSON

CVE-2023-26475

9.9
CRITICAL · CVSS 3.1 · EPSS 63.6% (pctl 99)

Patch early

EPSS 63.6% — above the 10% action threshold.

Description

XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. There is no easy workaround except to upgrade.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS63.59% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-269
On CISA KEVno
Public exploitnone known
Published2023-03-02
Last modified2026-06-17

Affected (1)

VendorProduct
xwikixwiki

References

→ the Explorer  ·  watch your stack  ·  NVD