← Vulnerability feed

Vulnerability record · CVE-2023-29525 · published 19 April 2023

CVE-2023-29525: XWiki Platform code injection in Notifications since parameter

Xwiki · Xwiki

XWiki Platform fails to escape the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint, allowing XWiki syntax injection. An authenticated user with only view rights can inject syntax that escalates to programming rights and then execute code. The flaw is patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3.

8.8 CVSS 3.1 High EPSS 78% · top 0.4% CWE-74 · Injection
8.8CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint. This provides an XWiki syntax injection attack via the since-parameter, allowing privilege escalation from view to programming rights and subsequent code execution privilege. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3. Users are advised to upgrade. Users unable to upgrade may modify the page `XWiki.Notifications.Code.LegacyNotificationAdministration` to add the missing escaping. For versions < 14.6-rc-1 a workaround is to modify the file `<xwikiwebapp>/templates/distribution/eventmigration.wiki` to add the missing escaping.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with low-privileged authenticated network access and public exploit references, though not in KEV.

What it is

XWiki Platform fails to escape the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint, allowing XWiki syntax injection. An authenticated user with only view rights can inject syntax that escalates to programming rights and then execute code. The flaw is patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8 and 14.10.3.

Impact

An attacker gains privilege escalation from view to programming rights and can execute arbitrary code on the XWiki server. This effectively gives full control over the application and its host.

Attack surface

Reached over the network via the LegacyNotificationAdministration endpoint with the `since` parameter. The CVSS vector shows PR:L, so a low-privileged authenticated account is required; no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.77752 (99.5th percentile) and the vendor advisory and Jira references are tagged Exploit, indicating public exploit information exists.

What to do

  • Upgrade to XWiki 15.0-rc-1, 14.10.3, 14.4.8 or later.
  • If upgrade is not possible, modify the page `XWiki.Notifications.Code.LegacyNotificationAdministration` to add the missing escaping.
  • For versions before 14.6-rc-1, modify `<xwikiwebapp>/templates/distribution/eventmigration.wiki` to add the missing escaping.
  • Restrict access to the LegacyNotificationAdministration endpoint and review accounts with view rights.

Detection

  • Monitor requests to `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` for unusual or encoded `since` parameter values.
  • Alert on XWiki syntax or scripting tokens appearing in the `since` parameter.
  • Audit XWiki logs for privilege changes to programming rights or unexpected code execution following notification administration requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29525 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2023-29525), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.