← Vulnerability feed

Vulnerability record · CVE-2022-36097 · published 8 September 2022

CVE-2022-36097: XWiki Platform Attachment UI stored XSS via attachment name

Xwiki · Xwiki

XWiki Platform Attachment UI allows JavaScript to be stored in an attachment name, which is then executed when a user moves that attachment. The flaw affects versions from 14.0-rc-1 up to 14.4-rc-1 and is patched in 14.4-rc-1. Because the script runs in the context of the moving user, it can compromise sessions and perform actions as that user.

6.1 CVSS 3.1 Medium EPSS 58% · top 0.9% CWE-79 · Cross-site scriptingCWE-80 · CWE-80
6.1CVSS 3.1 base score
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which will be executed by anyone trying to move the corresponding attachment. This issue has been patched in XWiki 14.4-rc-1. As a workaround, one may copy `moveStep1.vm` to `webapp/xwiki/templates/moveStep1.vm` and replace vulnerable code with code from the patch.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityAlthough CVSS is medium, the high EPSS score and public exploit references indicate active interest and a realistic risk for unpatched XWiki instances.

What it is

XWiki Platform Attachment UI allows JavaScript to be stored in an attachment name, which is then executed when a user moves that attachment. The flaw affects versions from 14.0-rc-1 up to 14.4-rc-1 and is patched in 14.4-rc-1. Because the script runs in the context of the moving user, it can compromise sessions and perform actions as that user.

Impact

An attacker can execute arbitrary JavaScript in the browser of any user who moves the malicious attachment, potentially stealing session cookies or performing actions with the victim's privileges. The CVSS vector indicates limited confidentiality and integrity impact within a changed scope.

Attack surface

The vulnerability is reachable over the network through the attachment move functionality. No authentication is required to trigger the stored payload, but user interaction is needed because a victim must attempt to move the affected attachment.

Exploitation

The record is not listed in CISA KEV, but EPSS is high at 0.57388 (99th percentile) and multiple references are tagged Exploit, indicating public exploit information exists.

What to do

  • Upgrade to XWiki 14.4-rc-1 or later, which contains the patch.
  • If immediate upgrade is not possible, apply the documented workaround by copying moveStep1.vm to webapp/xwiki/templates/moveStep1.vm and replacing the vulnerable code with the patched version.
  • Restrict attachment upload and move permissions to trusted users until the patch is applied.
  • Review and sanitize existing attachment names for embedded JavaScript or HTML.
  • Monitor XWiki security advisories for any further updates or backports.

Detection

  • Search XWiki attachment names for suspicious characters such as angle brackets, script tags, or JavaScript event handlers.
  • Monitor web server and application logs for requests to the attachment move endpoint with unusual or encoded attachment names.
  • Alert on unexpected JavaScript execution or DOM changes during attachment move operations in client-side monitoring.
  • Audit user reports of unexpected pop-ups or redirects when moving attachments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36097 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2022-36097), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.