CVE-2023-26475
9.9
CRITICAL · CVSS 3.1 · EPSS 63.6% (pctl 99)
Patch early
EPSS 63.6% — above the 10% action threshold.
Description
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. There is no easy workaround except to upgrade.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 63.59% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-269 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-03-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| xwiki | xwiki |
References
- https://github.com/xwiki/xwiki-platform/commit/d87d7bfd8db18c20d3264f98c6deefeae93b99f7
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h6f5-8jj5-cxhr
- https://jira.xwiki.org/browse/XWIKI-20360
- https://jira.xwiki.org/browse/XWIKI-20384
- https://github.com/xwiki/xwiki-platform/commit/d87d7bfd8db18c20d3264f98c6deefeae93b99f7
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h6f5-8jj5-cxhr
- https://jira.xwiki.org/browse/XWIKI-20360
- https://jira.xwiki.org/browse/XWIKI-20384
→ the Explorer · watch your stack · NVD