CVE-2023-27480: XWiki
High severity, CVSS 7.7. EPSS: 0.7% chance of exploitation in the next 30 days.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the XWiki server host. This vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10-rc-1. Users are advised to upgrade. Users unable to upgrade may apply the patch `e3527b98fd` manually.
Affected products
- XWiki XWiki: after 1.1, before 13.10.11 (fixed in 13.10.11); from 14.0, before 14.4.7 (fixed in 14.4.7); from 14.5, before 14.10 (fixed in 14.10); version 1.1 only
Published 2023-03-07. Last modified 2026-06-17.