Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-35150

70
FAUCET Score

CVE-2023-35150 identifies a critical arbitrary code injection vulnerability in XWiki Platform versions prior to 14.4.8, 14.10.4, and 15.0. This flaw allows any authenticated user with view rights on a document to achieve remote code execution by crafting a malicious URL. Rated with a CVSS score of 8.0 (High), the vulnerability has a network attack vector and low attack complexity, requiring only low privileges and user interaction to achieve high confidentiality, integrity, and availability impacts. Although not yet on CISA's KEV catalog, it is on the "Hot List" and has generated significant community discussion and detailed analysis by security researchers, despite no public exploit code being readily available.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.5, < 14.4.8CPE matchmatch criteria
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
>= 14.10, < 14.10.4CPE matchmatch criteria
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
2.4CPE matchmatch criteria
cpe:2.3:a:xwiki:xwiki:2.4:milestone2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
77.65%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.7765 is in the 100th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.xwiki.platform:xwiki-platform-invitation-uiFixed in: 14.4.8
mavenpatch availablevia ghsa
Product: org.xwiki.platform:xwiki-platform-invitation-uiFixed in: 14.10.4
mavenpatch availablevia ghsa
Product: org.xwiki.platform:xwiki-platform-invitation-uiFixed in: 15.0

Vendor Advisories (1)

mavenGHSA-6mf5-36v9-3h2wcritical

XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application

Jun 20, 2023

References

github.com / xwiki/xwiki-platform/commit/b65220a4d86b8888791c3b643074ebca5c089a3a
PatchVendor Advisory
github.com / xwiki/xwiki-platform/security/advisories/GHSA-6mf5-36v9-3h2w
Vendor Advisory
jira.xwiki.org / browse/XWIKI-20285
ExploitIssue TrackingPatchVendor Advisory