CVE-2023-32070

CRITICAL

Xwiki Rendering < 14.5 - XSS

Title source: rule

Description

XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.

Exploits (1)

nomisec STUB
by shoucheng3 · poc
https://github.com/shoucheng3/xwiki__xwiki-rendering_CVE-2023-32070_14-5

Scores

CVSS v3 9.0
EPSS 0.0466
EPSS Percentile 89.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-83 CWE-79
Status published
Products (9)
org.xwiki.platform/xwiki-core-rendering-api 0Maven
org.xwiki.platform/xwiki-platform-annotation-core 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-annotatedhtml5 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-annotatedxhtml 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-html 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-html5 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-xhtml 0 - 14.6-rc-1Maven
xwiki/rendering 3.0 milestone_2
xwiki/xwiki < 14.5
Published May 10, 2023
Tracked Since Feb 18, 2026