Vulnerability record · CVE-2024-31997 · published 10 April 2024
CVE-2024-31997: XWiki UI extension parameters execute as Velocity code, enabling RCE
Xwiki · Xwiki
XWiki Platform interprets UI extension parameters as Velocity code and executes them with programming rights, and any user with edit rights on a document (such as their own profile) can create UI extensions. This lets a low-privileged authenticated user run arbitrary code on the server, affecting the confidentiality, integrity and availability of the entire installation. The flaw is a missing authorization check (CWE-862) and is patched in XWiki 14.10.19, 15.5.4 and 15.9-RC1, with no known workarounds.
Description
XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the user's own profile can create UI extensions. This allows remote code execution and thereby impacts the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.19, 15.5.4 and 15.9-RC1. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high EPSS and public exploit references, though it requires an authenticated low-privileged account and is not in KEV.
What it is
XWiki Platform interprets UI extension parameters as Velocity code and executes them with programming rights, and any user with edit rights on a document (such as their own profile) can create UI extensions. This lets a low-privileged authenticated user run arbitrary code on the server, affecting the confidentiality, integrity and availability of the entire installation. The flaw is a missing authorization check (CWE-862) and is patched in XWiki 14.10.19, 15.5.4 and 15.9-RC1, with no known workarounds.
Impact
An attacker gains remote code execution with the privileges of the XWiki server process, allowing full compromise of data and the application. Because the whole installation is affected, confidentiality, integrity and availability are all rated high.
Attack surface
Reachable over the network through the web interface; the attacker needs an authenticated account with edit rights on at least one document, such as their own profile, and no user interaction is required. The CVSS vector confirms network access, low privileges and no UI interaction.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.739 probability, 99.5th percentile) and the vendor advisory and Jira references are tagged Exploit, indicating public exploit information exists. No ransomware group is documented as using it.
What to do
- Upgrade to XWiki 14.10.19, 15.5.4 or 15.9-RC1 (or later) as soon as possible.
- If immediate patching is not possible, restrict edit rights so untrusted users cannot create or modify UI extensions; note the vendor states no official workaround exists.
- Review and remove any unauthorized UI extensions or documents created by low-privileged accounts.
- Limit the programming rights granted to the XWiki application account and monitor for unexpected privilege use.
- Audit accounts with edit rights and reduce them to the minimum needed.
Detection
- Search XWiki logs and documents for newly created or modified UI extensions, especially those authored by non-administrative users.
- Monitor for Velocity code execution patterns or suspicious script content in extension parameters.
- Alert on unexpected outbound connections or process spawning from the XWiki server.
- Track authentication and edit events for accounts that create extensions shortly after login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-31997 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-31997), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.