← Vulnerability feed

Vulnerability record · CVE-2023-35150 · published 23 June 2023

CVE-2023-35150: XWiki Platform code injection lets any viewer execute code with programming rights

Xwiki · Xwiki

XWiki Platform fails to properly restrict code execution, so any user with view rights on a document can execute code with programming rights by crafting a URL containing a dangerous payload. This turns a low-privileged wiki account into remote code execution on the server. Patches exist in XWiki 15.0, 14.10.4 and 14.4.8.

8.0 CVSS 3.1 High EPSS 78% · top 0.4% CWE-95 · CWE-95CWE-94 · Code injection
8.0CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to remote code execution by crafting an url with a dangerous payload. The problem has been patched in XWiki 15.0, 14.10.4 and 14.4.8.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution reachable by any user with view rights, with a patch available and very high EPSS, though not in KEV.

What it is

XWiki Platform fails to properly restrict code execution, so any user with view rights on a document can execute code with programming rights by crafting a URL containing a dangerous payload. This turns a low-privileged wiki account into remote code execution on the server. Patches exist in XWiki 15.0, 14.10.4 and 14.4.8.

Impact

An attacker gains remote code execution with the privileges of the XWiki server process, allowing full compromise of the wiki host and any data or credentials it can reach.

Attack surface

Reachable over the network via a crafted URL; the attacker needs an account with view rights on at least one document, and the CVSS vector indicates user interaction is required. No elevated privileges are needed beyond basic view access.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.776, 99.5th percentile) and a vendor JIRA reference is tagged Exploit, indicating public exploit detail is available. No ransomware usage is documented.

What to do

  • Upgrade to XWiki 15.0, 14.10.4 or 14.4.8 (or later) immediately.
  • If patching is delayed, restrict view rights and anonymous access so untrusted users cannot reach documents.
  • Review and remove unnecessary programming rights from documents and authors.
  • Monitor XWiki logs and web traffic for crafted URLs containing code payloads.
  • Apply network controls to limit outbound and lateral movement from the XWiki host.

Detection

  • Search web/proxy logs for XWiki requests with encoded or script-like payloads in URL parameters.
  • Alert on XWiki processes spawning unexpected child processes or shells.
  • Audit XWiki documents and revisions for newly added code using programming rights.
  • Monitor for unusual outbound connections from the XWiki server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-35150 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2023-35150), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.