← Vulnerability feed

Vulnerability record · CVE-2022-36096 · published 8 September 2022

CVE-2022-36096: XWiki Deleted Attachments Index stored XSS via attachment filename

Xwiki · Xwiki

XWiki Platform's Index UI fails to sanitize attachment names shown in the deleted attachments index, allowing JavaScript stored in an attachment filename to execute when a user views that index. The flaw affects versions prior to 13.10.6 and 14.3 and is patched in those releases. Because the payload persists in the wiki and fires for any viewer of the index, it enables session and content compromise across users.

9.0 CVSS 3.1 Critical EPSS 60% · top 0.9% CWE-79 · Cross-site scriptingCWE-80 · CWE-80
9.0CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3. As a workaround, modify fix the vulnerability by editing the wiki page `XWiki.DeletedAttachments` with the object editor, open the `JavaScriptExtension` object and apply on the content the changes that can be found on the fix commit.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCritical CVSS (9.0) stored XSS with high EPSS, but exploitation requires authentication and user interaction and no KEV listing or confirmed in-the-wild use is recorded.

What it is

XWiki Platform's Index UI fails to sanitize attachment names shown in the deleted attachments index, allowing JavaScript stored in an attachment filename to execute when a user views that index. The flaw affects versions prior to 13.10.6 and 14.3 and is patched in those releases. Because the payload persists in the wiki and fires for any viewer of the index, it enables session and content compromise across users.

Impact

An attacker can execute arbitrary JavaScript in the browser of any user viewing the deleted attachments index, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component to the user's session and the wider wiki.

Attack surface

Reachable over the network through the XWiki web interface; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), meaning an authenticated user must create or upload the maliciously named attachment and a victim must view the deleted attachments index. No unauthenticated path is described.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.59 (99th percentile), suggesting elevated likelihood of attempted exploitation, but the record provides no confirmed in-the-wild exploitation evidence.

What to do

  • Upgrade XWiki to 13.10.6 or 14.3 or later.
  • If immediate upgrade is not possible, apply the documented workaround: edit the wiki page XWiki.DeletedAttachments with the object editor, open the JavaScriptExtension object, and apply the changes from the fix commit.
  • Restrict who can create or upload attachments and review attachment names for script content.
  • Audit existing attachment names and the deleted attachments index for injected JavaScript.
  • Monitor XWiki security advisories for follow-up fixes.

Detection

  • Search attachment names and the deleted attachments index for script tags, event handlers, or javascript: payloads.
  • Review web and application logs for requests to the deleted attachments index with suspicious attachment names.
  • Monitor for anomalous authenticated sessions or actions following views of the deleted attachments index.
  • Check XWiki version inventory against the fixed versions 13.10.6 and 14.3.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36096 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2022-36096), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.