← Vulnerability feed

Vulnerability record · CVE-2023-37462 · published 14 July 2023

CVE-2023-37462: XWiki Platform improper escaping in XWikiSkinsSheet enables script injection and RCE

Xwiki · Xwiki

XWiki Platform fails to properly escape content in the document SkinsCode.XWikiSkinsSheet, creating an injection vector that escalates view rights on that document to programming rights. This allows execution of arbitrary script macros, including Groovy and Python, resulting in remote code execution with unrestricted read and write access to all wiki contents. The flaw is triggered by opening a non-existing page whose name is crafted to contain a dangerous payload.

8.8 CVSS 3.1 High EPSS 92% · top 0.2% CWE-74 · InjectionCWE-95 · CWE-95
8.8CVSS 3.1 base score
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The attack works by opening a non-existing page with a name crafted to contain a dangerous payload. It is possible to check if an existing installation is vulnerable. See the linked GHSA for instructions on testing an installation. This issue has been patched in XWiki 14.4.8, 14.10.4 and 15.0-rc-1. Users are advised to upgrade. The fix commit `d9c88ddc` can also be applied manually to the impacted document `SkinsCode.XWikiSkinsSheet` and users unable to upgrade are advised to manually patch their installations.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with high confidentiality, integrity and availability impact plus a very high EPSS score and public exploit references make this a serious risk, though it requires low privileges and is not in KEV.

What it is

XWiki Platform fails to properly escape content in the document SkinsCode.XWikiSkinsSheet, creating an injection vector that escalates view rights on that document to programming rights. This allows execution of arbitrary script macros, including Groovy and Python, resulting in remote code execution with unrestricted read and write access to all wiki contents. The flaw is triggered by opening a non-existing page whose name is crafted to contain a dangerous payload.

Impact

An attacker gains programming rights and can execute arbitrary Groovy or Python macros, leading to remote code execution and full read/write access to all wiki content. This effectively compromises the confidentiality, integrity and availability of the entire wiki instance.

Attack surface

The vector is network-reachable (AV:N) with low attack complexity and no user interaction, but requires low privileges (PR:L), meaning an authenticated user with basic view access can trigger it. The attack is delivered by requesting a non-existing page with a specially crafted name.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high at 0.91592 (99.8th percentile), and multiple references are tagged Exploit, indicating public exploit information exists. No ransomware group usage is documented.

What to do

  • Upgrade to XWiki 14.4.8, 14.10.4 or 15.0-rc-1 or later, which contain the fix.
  • If upgrading is not possible, manually apply fix commit d9c88ddc to the impacted document SkinsCode.XWikiSkinsSheet.
  • Restrict the ability of untrusted users to create or view pages, and review who holds programming rights.
  • Monitor for and remove any unexpected pages with crafted names that could carry injection payloads.
  • Use the vendor GHSA instructions to check whether an existing installation is vulnerable.

Detection

  • Search wiki logs and page creation records for non-existing page requests with unusual or macro-like characters in the page name.
  • Monitor for unexpected execution of Groovy or Python macros and for changes to wiki content made by low-privileged accounts.
  • Alert on access to SkinsCode.XWikiSkinsSheet by users who do not normally interact with skin documents.
  • Review audit logs for privilege escalation to programming rights or unexpected document edits.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-37462 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2023-37462), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.