← Vulnerability feed

Vulnerability record · CVE-2023-29509 · published 16 April 2023

CVE-2023-29509: XWiki documentTree macro parameter escaping allows code injection

Xwiki · Xwiki

XWiki Commons fails to properly escape parameters of the documentTree macro, which is installed by default in FlamingoThemesCode.WebHome. Any user with view rights on commonly accessible documents can inject and execute arbitrary Groovy, Python or Velocity code. This gives full access to the XWiki installation.

8.8 CVSS 3.1 High EPSS 76% · top 0.5% CWE-95 · CWE-95CWE-94 · Code injection
8.8CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `documentTree` macro parameters in This macro is installed by default in `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 and very high EPSS with a public exploit reference make this a serious remote code execution risk for unpatched XWiki instances, though it requires authenticated view access.

What it is

XWiki Commons fails to properly escape parameters of the documentTree macro, which is installed by default in FlamingoThemesCode.WebHome. Any user with view rights on commonly accessible documents can inject and execute arbitrary Groovy, Python or Velocity code. This gives full access to the XWiki installation.

Impact

An authenticated low-privileged user can execute arbitrary server-side code and gain full control of the XWiki installation, including reading or modifying all content and potentially executing commands on the host.

Attack surface

Reachable over the network through the web interface by any user with view rights on commonly accessible documents; no user interaction is required beyond submitting the crafted macro parameters.

Exploitation

No CISA KEV listing, but EPSS is very high (0.75693, 99.5th percentile) and a vendor issue-tracking reference is tagged Exploit, indicating public exploit information exists.

What to do

  • Upgrade XWiki to 13.10.11, 14.4.7, 14.10 or later as specified in the vendor advisory.
  • If immediate upgrade is not possible, restrict view rights on commonly accessible documents and the FlamingoThemesCode.WebHome page to trusted users only.
  • Disable or remove the documentTree macro from default theme pages where it is not required.
  • Review and restrict the set of users with even basic view access to the wiki until patched.
  • Monitor XWiki logs for unexpected Groovy, Python or Velocity execution errors.

Detection

  • Search XWiki request logs for documentTree macro invocations containing script-like or unusual parameter values.
  • Monitor for unexpected Groovy, Python or Velocity script execution or related errors in XWiki application logs.
  • Audit changes to FlamingoThemesCode.WebHome and other default theme pages for unauthorized modifications.
  • Alert on creation or modification of wiki pages by low-privileged users that include macro parameters with code-like content.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29509 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2023-29509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.