Vulnerability record · CVE-2022-36096 · published 8 September 2022
CVE-2022-36096: XWiki Deleted Attachments Index stored XSS via attachment filename
Xwiki · Xwiki
XWiki Platform's Index UI fails to sanitize attachment names shown in the deleted attachments index, allowing JavaScript stored in an attachment filename to execute when a user views that index. The flaw affects versions prior to 13.10.6 and 14.3 and is patched in those releases. Because the payload persists in the wiki and fires for any viewer of the index, it enables session and content compromise across users.
Description
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3. As a workaround, modify fix the vulnerability by editing the wiki page `XWiki.DeletedAttachments` with the object editor, open the `JavaScriptExtension` object and apply on the content the changes that can be found on the fix commit.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS (9.0) stored XSS with high EPSS, but exploitation requires authentication and user interaction and no KEV listing or confirmed in-the-wild use is recorded.
What it is
XWiki Platform's Index UI fails to sanitize attachment names shown in the deleted attachments index, allowing JavaScript stored in an attachment filename to execute when a user views that index. The flaw affects versions prior to 13.10.6 and 14.3 and is patched in those releases. Because the payload persists in the wiki and fires for any viewer of the index, it enables session and content compromise across users.
Impact
An attacker can execute arbitrary JavaScript in the browser of any user viewing the deleted attachments index, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component to the user's session and the wider wiki.
Attack surface
Reachable over the network through the XWiki web interface; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), meaning an authenticated user must create or upload the maliciously named attachment and a victim must view the deleted attachments index. No unauthenticated path is described.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.59 (99th percentile), suggesting elevated likelihood of attempted exploitation, but the record provides no confirmed in-the-wild exploitation evidence.
What to do
- Upgrade XWiki to 13.10.6 or 14.3 or later.
- If immediate upgrade is not possible, apply the documented workaround: edit the wiki page XWiki.DeletedAttachments with the object editor, open the JavaScriptExtension object, and apply the changes from the fix commit.
- Restrict who can create or upload attachments and review attachment names for script content.
- Audit existing attachment names and the deleted attachments index for injected JavaScript.
- Monitor XWiki security advisories for follow-up fixes.
Detection
- Search attachment names and the deleted attachments index for script tags, event handlers, or javascript: payloads.
- Review web and application logs for requests to the deleted attachments index with suspicious attachment names.
- Monitor for anomalous authenticated sessions or actions following views of the deleted attachments index.
- Check XWiki version inventory against the fixed versions 13.10.6 and 14.3.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/6705b0cd0289d1c90ed354bd4ecc1508c4b25745 | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gjmq-x5x7-wc36 | Third Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19613 | Vendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/6705b0cd0289d1c90ed354bd4ecc1508c4b25745 | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gjmq-x5x7-wc36 | Third Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19613 | Vendor Advisory |
Track CVE-2022-36096 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36096), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.