Vulnerability record · CVE-2022-36100 · published 8 September 2022
CVE-2022-36100: XWiki Tag UI document allows code injection with programming rights
Xwiki · Xwiki
The Main.Tags document in XWiki Platform Applications Tag and Tag UI did not sanitize user input, letting users with view rights execute arbitrary Groovy, Python and Velocity code with programming rights. This breaks all rights checks, allowing modification and disclosure of all wiki content and impacting availability. Patched in 13.10.6 and 14.4.
Description
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document `Main.Tags` in XWiki didn't sanitize user inputs properly. This allowed users with view rights on the document (default in a public wiki or for authenticated users on private wikis) to execute arbitrary Groovy, Python and Velocity code with programming rights. This also allowed bypassing all rights checks and thus both modification and disclosure of all content stored in the XWiki installation. The vulnerability could be used to impact the availability of the wiki. On XWiki versions before 13.10.4 and 14.2, this can be combined with CVE-2022-36092, meaning that no rights are required to perform the attack. The vulnerability has been patched in versions 13.10.6 and 14.4. As a workaround, the patch that fixes the issue can be manually applied to the document `Main.Tags` or the updated version of that document can be imported from version 14.4 of xwiki-platform-tag-ui using the import feature in the administration UI on XWiki 10.9 and later.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low privileges and no user interaction, plus very high EPSS and public exploit references, make this a high-priority patch despite no KEV listing.
What it is
The Main.Tags document in XWiki Platform Applications Tag and Tag UI did not sanitize user input, letting users with view rights execute arbitrary Groovy, Python and Velocity code with programming rights. This breaks all rights checks, allowing modification and disclosure of all wiki content and impacting availability. Patched in 13.10.6 and 14.4.
Impact
An attacker gains code execution with programming rights, can bypass all access controls, read or modify any stored content, and degrade wiki availability.
Attack surface
Reached remotely over the network through the tags document; only view rights on that document are needed (default for public wikis or authenticated users on private wikis), with no user interaction. On versions before 13.10.4 and 14.2, chaining with CVE-2022-36092 removes the rights requirement entirely.
Exploitation
Not listed in CISA KEV, but EPSS is 0.73608 (99.4th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade to XWiki 13.10.6 or 14.4 (or later) to apply the official patch.
- If immediate upgrade is not possible, manually apply the patch to the Main.Tags document or import the updated document from xwiki-platform-tag-ui 14.4 via the administration import feature on XWiki 10.9 and later.
- Restrict view rights on Main.Tags and limit wiki access to trusted users until patched.
- Review and revert any unexpected changes to wiki content or configuration that may indicate prior exploitation.
Detection
- Monitor wiki logs and audit trails for edits or requests touching Main.Tags outside normal administrative activity.
- Alert on Groovy, Python or Velocity code execution events originating from tag document rendering.
- Hunt for anomalous content modifications or mass data access consistent with rights bypass.
- Correlate with exploitation attempts of CVE-2022-36092 on versions before 13.10.4 and 14.2.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/604868033ebd191cf2d1e94db336f0c4d9096427 | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-2g5c-228j-p52x | ExploitPatchThird Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19747 | ExploitVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/604868033ebd191cf2d1e94db336f0c4d9096427 | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-2g5c-228j-p52x | ExploitPatchThird Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19747 | ExploitVendor Advisory |
Track CVE-2022-36100 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36100), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.