← Vulnerability feed

Vulnerability record · CVE-2023-36469 · published 29 June 2023

CVE-2023-36469: XWiki Platform script macro injection in notification settings allows RCE

Xwiki · Xwiki

XWiki Platform lets any user who can edit their own profile and notification settings inject script macros, including Groovy and Python, through the notification RSS service. Because those macros execute server-side, a low-privileged user can run arbitrary code and read or write all wiki contents. The flaw is patched in XWiki 14.10.6 and 15.2RC1.

8.8 CVSS 3.1 High EPSS 82% · top 0.4% CWE-74 · Injection
8.8CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. This has been patched in XWiki 14.10.6 and 15.2RC1. Users are advised to update. As a workaround the main security fix can be manually applied by patching the affected document `XWiki.Notifications.Code.NotificationRSSService`. This will break the link to the differences, though as this requires additional changes to Velocity templates as shown in the patch. While the default template is available in the instance and can be easily patched, the template for mentions is contained in a `.jar`-file and thus cannot be fixed without replacing that jar.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with low-privileged network access, full confidentiality, integrity and availability impact, and very high EPSS despite no KEV listing.

What it is

XWiki Platform lets any user who can edit their own profile and notification settings inject script macros, including Groovy and Python, through the notification RSS service. Because those macros execute server-side, a low-privileged user can run arbitrary code and read or write all wiki contents. The flaw is patched in XWiki 14.10.6 and 15.2RC1.

Impact

An authenticated low-privileged user gains remote code execution on the XWiki server, with unrestricted read and write access to all wiki contents. This effectively escalates a normal account to full control over the platform and its data.

Attack surface

Reached over the network through the notification settings and RSS service of XWiki; the CVSS vector shows PR:L and UI:N, so a low-privileged authenticated account is required but no victim interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.82032 (99.6th percentile) and the vendor advisory and Jira references are tagged Exploit, indicating public exploit detail exists.

What to do

  • Upgrade to XWiki 14.10.6 or 15.2RC1 (or later) as the primary fix.
  • If immediate upgrade is not possible, manually apply the patch to the XWiki.Notifications.Code.NotificationRSSService document as described in the advisory.
  • Note that the workaround breaks the differences link and that the mentions template lives in a .jar, so it cannot be fixed without replacing that jar; plan the full upgrade.
  • Restrict who can edit profiles and notification settings until patched, and review accounts with those rights.
  • Monitor XWiki logs and content changes for unexpected Groovy or Python macro execution.

Detection

  • Search XWiki documents and notification settings for injected Groovy or Python macro syntax.
  • Alert on unexpected server-side script execution or child processes spawned by the XWiki application.
  • Review changes to XWiki.Notifications.Code.NotificationRSSService and related Velocity templates for unauthorized edits.
  • Monitor for outbound connections or file writes from the XWiki host consistent with post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-36469 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2023-36469), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.