CVE-2023-32070

CRITICAL

XWiki Platform < 14.6-rc-1 - Cross-Site Scripting via HTML Attribute Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-32070. PoCs published by shoucheng3.

AI-analyzed exploit summary The repository contains only source code files from the XWiki Rendering project and a README, with no exploit PoC or offensive techniques present. It appears to be a partial snapshot of the project rather than a functional exploit.

Description

XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.

Exploits (1)

nomisec STUB
by shoucheng3 · poc
https://github.com/shoucheng3/xwiki__xwiki-rendering_CVE-2023-32070_14-5

The repository contains only source code files from the XWiki Rendering project and a README, with no exploit PoC or offensive techniques present. It appears to be a partial snapshot of the project rather than a functional exploit.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: XWiki Rendering (version unspecified)
No auth needed
Prerequisites: None identified
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.0
EPSS 0.2190
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-83 CWE-79
Status published
Products (9)
org.xwiki.platform/xwiki-core-rendering-api 0Maven
org.xwiki.platform/xwiki-platform-annotation-core 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-annotatedhtml5 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-annotatedxhtml 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-html 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-html5 0 - 14.6-rc-1Maven
org.xwiki.rendering/xwiki-rendering-syntax-xhtml 0 - 14.6-rc-1Maven
xwiki/rendering 3.0 milestone_2
xwiki/xwiki < 14.5
Published May 10, 2023
Tracked Since Feb 18, 2026