CVE-2024-55662
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed in XWiki 15.10.9 and 16.3.0. Since `Extension Repository Application` is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer`.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.76%
- CWE
- CWE-96, CWE-863
- Published
- 2024-12-12
- Last modified
- 2026-03-13
Affected products
- xwiki xwiki-platform
- xwiki xwiki-platform
Weakness type
Related vulnerabilities
- CVE-2024-55877 — XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2020-6144 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh
- CVE-2020-6143 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable wh
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allo
- CVE-2022-43938 — Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
- CVE-2024-43400 — XWiki Platform allows XSS through XClass name in string properties