CVE-2014-8658: Refinedwiki Original Theme

Medium severity, CVSS 4.0. EPSS: 1.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote authenticated users with permissions to create or edit content to inject arbitrary web script or HTML via the versionComment parameter to pages/doeditpage.action.

Affected products

  • Refinedwiki Refinedwiki Original Theme: version 3.5 only; version 3.5.1 only; version 3.5.2 only; version 3.5.3 only; version 3.5.4 only; version 3.5.5 only; …

Published 2014-11-06. Last modified 2026-06-17.