CVE-2023-26055
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in all other places where short text properties are displayed, e.g., in apps created using Apps Within Minutes that use a short text field. The problem has been patched on versions 13.10.9, 14.4.4, 14.7RC1.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.33%
- CWE
- CWE-150
- Published
- 2023-03-02
- Last modified
- 2026-03-13
Affected products
- xwiki xwiki-commons
- xwiki xwiki-commons
- xwiki xwiki-commons
Weakness type
Related vulnerabilities
- CVE-2025-55754 — Apache Tomcat: console manipulation via escape sequences in log messages
- CVE-2020-6932 — An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Softwa
- CVE-2025-25286 — Crayfish allows Remote Code Execution via Homarus Authorization header
- CVE-2025-47284 — Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
- CVE-2023-3265 — An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the user
- CVE-2024-32986 — Arbitrary code execution due to improper sanitization of web app properties in PWAsForFirefox
- CVE-2023-28446 — Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization
- CVE-2025-0975 — IBM MQ code execution