CVE-2023-26056: XWiki

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-1, 14.4.5, and 13.10.10. There are no known workarounds for this issue.

Affected products

  • XWiki XWiki: from 3.1, before 13.10.10 (fixed in 13.10.10); from 14.0, before 14.4.5 (fixed in 14.4.5); from 14.5, before 14.8 (fixed in 14.8); version 3.0 only

Published 2023-03-02. Last modified 2026-06-17.