← Vulnerability feed

Vulnerability record · CVE-2023-35166 · published 20 June 2023

CVE-2023-35166: XWiki Platform authorization flaw allows wiki content execution as TipsPanel author

Xwiki · Xwiki

XWiki Platform has an incorrect authorization flaw (CWE-863) where a user can execute arbitrary wiki content with the rights of the TipsPanel author by creating a tip UI extension. This matters because it lets a low-privileged user escalate to the privileges of the TipsPanel author and run content they should not be able to run. It is patched in XWiki 15.1-rc-1 and 14.10.5.

8.8 CVSS 3.1 High EPSS 62% · top 0.8% CWE-863 · Incorrect authorization
8.8CVSS 3.1 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with low-privileged network access and high EPSS, but no confirmed in-the-wild exploitation or KEV listing.

What it is

XWiki Platform has an incorrect authorization flaw (CWE-863) where a user can execute arbitrary wiki content with the rights of the TipsPanel author by creating a tip UI extension. This matters because it lets a low-privileged user escalate to the privileges of the TipsPanel author and run content they should not be able to run. It is patched in XWiki 15.1-rc-1 and 14.10.5.

Impact

An attacker with a low-privileged account gains the ability to execute wiki content under the TipsPanel author's rights, which can lead to unauthorized actions and data exposure within the wiki. The CVSS vector indicates high confidentiality, integrity, and availability impact.

Attack surface

The flaw is reachable over the network via the wiki UI extension mechanism, requiring a low-privileged authenticated account and no user interaction. The CVSS vector is AV:N/AC:L/PR:L/UI:N.

Exploitation

No CISA KEV listing is present, but EPSS is 0.62172 (99.1st percentile) and a vendor Jira reference is tagged Exploit, indicating public exploit information exists.

What to do

  • Upgrade XWiki to 15.1-rc-1 or 14.10.5 or later.
  • If immediate upgrade is not possible, restrict who can create tip UI extensions and review existing tip extensions for unauthorized content.
  • Limit the privileges of the TipsPanel author account and audit accounts with elevated wiki content execution rights.
  • Monitor vendor advisories and the referenced patch commit for backport guidance on older branches.

Detection

  • Audit creation and modification of tip UI extensions in XWiki and alert on unexpected authors.
  • Review wiki content execution logs for actions performed under the TipsPanel author account that do not match normal administrative activity.
  • Search for the referenced Jira issue XWIKI-20281 and patch commit in change-management records to confirm remediation status.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-35166 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2023-35166), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.