CVE-2023-29513: XWiki
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has view right on any document. It's possible to create a new user using the `distribution/firstadminuser.wiki` in the wrong context. This vulnerability has been patched in XWiki 15.0-rc-1 and 14.10.1. There is no known workaround other than upgrading.
Affected products
- XWiki XWiki: before 14.10.1 (fixed in 14.10.1)
Published 2023-04-19. Last modified 2026-06-17.