Vulnerability record · CVE-2023-29509 · published 16 April 2023
CVE-2023-29509: XWiki documentTree macro parameter escaping allows code injection
Xwiki · Xwiki
XWiki Commons fails to properly escape parameters of the documentTree macro, which is installed by default in FlamingoThemesCode.WebHome. Any user with view rights on commonly accessible documents can inject and execute arbitrary Groovy, Python or Velocity code. This gives full access to the XWiki installation.
Description
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `documentTree` macro parameters in This macro is installed by default in `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and very high EPSS with a public exploit reference make this a serious remote code execution risk for unpatched XWiki instances, though it requires authenticated view access.
What it is
XWiki Commons fails to properly escape parameters of the documentTree macro, which is installed by default in FlamingoThemesCode.WebHome. Any user with view rights on commonly accessible documents can inject and execute arbitrary Groovy, Python or Velocity code. This gives full access to the XWiki installation.
Impact
An authenticated low-privileged user can execute arbitrary server-side code and gain full control of the XWiki installation, including reading or modifying all content and potentially executing commands on the host.
Attack surface
Reachable over the network through the web interface by any user with view rights on commonly accessible documents; no user interaction is required beyond submitting the crafted macro parameters.
Exploitation
No CISA KEV listing, but EPSS is very high (0.75693, 99.5th percentile) and a vendor issue-tracking reference is tagged Exploit, indicating public exploit information exists.
What to do
- Upgrade XWiki to 13.10.11, 14.4.7, 14.10 or later as specified in the vendor advisory.
- If immediate upgrade is not possible, restrict view rights on commonly accessible documents and the FlamingoThemesCode.WebHome page to trusted users only.
- Disable or remove the documentTree macro from default theme pages where it is not required.
- Review and restrict the set of users with even basic view access to the wiki until patched.
- Monitor XWiki logs for unexpected Groovy, Python or Velocity execution errors.
Detection
- Search XWiki request logs for documentTree macro invocations containing script-like or unusual parameter values.
- Monitor for unexpected Groovy, Python or Velocity script execution or related errors in XWiki application logs.
- Audit changes to FlamingoThemesCode.WebHome and other default theme pages for unauthorized modifications.
- Alert on creation or modification of wiki pages by low-privileged users that include macro parameters with code-like content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/80d5be36f700adcd56b6c8eb3ed8b973f62ec0ae | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-f4v8-58f6-mwj4 | PatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20279 | ExploitIssue TrackingVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/80d5be36f700adcd56b6c8eb3ed8b973f62ec0ae | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-f4v8-58f6-mwj4 | PatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-20279 | ExploitIssue TrackingVendor Advisory |
Track CVE-2023-29509 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.