CVE-2023-32069: XWiki

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patched in XWiki 15.0-rc-1 and 14.10.4. There are no known workarounds.

Affected products

  • XWiki XWiki: from 3.4, before 14.10.4 (fixed in 14.10.4); version 3.3 only

Published 2023-05-09. Last modified 2026-06-17.