← Vulnerability feed

Vulnerability record · CVE-2022-36100 · published 8 September 2022

CVE-2022-36100: XWiki Tag UI document allows code injection with programming rights

Xwiki · Xwiki

The Main.Tags document in XWiki Platform Applications Tag and Tag UI did not sanitize user input, letting users with view rights execute arbitrary Groovy, Python and Velocity code with programming rights. This breaks all rights checks, allowing modification and disclosure of all wiki content and impacting availability. Patched in 13.10.6 and 14.4.

8.8 CVSS 3.1 High EPSS 74% · top 0.5% CWE-94 · Code injectionCWE-95 · CWE-95
8.8CVSS 3.1 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document `Main.Tags` in XWiki didn't sanitize user inputs properly. This allowed users with view rights on the document (default in a public wiki or for authenticated users on private wikis) to execute arbitrary Groovy, Python and Velocity code with programming rights. This also allowed bypassing all rights checks and thus both modification and disclosure of all content stored in the XWiki installation. The vulnerability could be used to impact the availability of the wiki. On XWiki versions before 13.10.4 and 14.2, this can be combined with CVE-2022-36092, meaning that no rights are required to perform the attack. The vulnerability has been patched in versions 13.10.6 and 14.4. As a workaround, the patch that fixes the issue can be manually applied to the document `Main.Tags` or the updated version of that document can be imported from version 14.4 of xwiki-platform-tag-ui using the import feature in the administration UI on XWiki 10.9 and later.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with low privileges and no user interaction, plus very high EPSS and public exploit references, make this a high-priority patch despite no KEV listing.

What it is

The Main.Tags document in XWiki Platform Applications Tag and Tag UI did not sanitize user input, letting users with view rights execute arbitrary Groovy, Python and Velocity code with programming rights. This breaks all rights checks, allowing modification and disclosure of all wiki content and impacting availability. Patched in 13.10.6 and 14.4.

Impact

An attacker gains code execution with programming rights, can bypass all access controls, read or modify any stored content, and degrade wiki availability.

Attack surface

Reached remotely over the network through the tags document; only view rights on that document are needed (default for public wikis or authenticated users on private wikis), with no user interaction. On versions before 13.10.4 and 14.2, chaining with CVE-2022-36092 removes the rights requirement entirely.

Exploitation

Not listed in CISA KEV, but EPSS is 0.73608 (99.4th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade to XWiki 13.10.6 or 14.4 (or later) to apply the official patch.
  • If immediate upgrade is not possible, manually apply the patch to the Main.Tags document or import the updated document from xwiki-platform-tag-ui 14.4 via the administration import feature on XWiki 10.9 and later.
  • Restrict view rights on Main.Tags and limit wiki access to trusted users until patched.
  • Review and revert any unexpected changes to wiki content or configuration that may indicate prior exploitation.

Detection

  • Monitor wiki logs and audit trails for edits or requests touching Main.Tags outside normal administrative activity.
  • Alert on Groovy, Python or Velocity code execution events originating from tag document rendering.
  • Hunt for anomalous content modifications or mass data access consistent with rights bypass.
  • Correlate with exploitation attempts of CVE-2022-36092 on versions before 13.10.4 and 14.2.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36100 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2022-36100), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.