XWiki is an open-source wiki and collaboration platform whose vulnerability footprint, despite a focused product portfolio, ranks among the most represented in the landscape, reflecting the platform's deep embeddedness in internal knowledge-management and documentation infrastructure. Vulnerabilities affecting the vendor skew strongly toward serious outcomes and frequently acquire public exploit code, driven by the platform's dynamic content-generation model and server-side code execution capabilities. The exposure recurs persistently across XWiki's core product, rendering libraries, and macro subsystems through interconnected weakness classes centered on improper neutralization of user input in dynamically evaluated contexts—cross-site scripting, code injection, eval injection, and missing authorization—that are structural to a wiki platform where users can contribute template-driven content with embedded expressions. Defenders should treat XWiki disclosures as high-priority for any internal wiki deployment and inventory instances that expose the platform to untrusted user submission; live severity, exploit availability, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xwiki over time
Signals from CVEs in this vendor scope (282 CVEs).
282 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-24893CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to | Feb 20, 2025 | 9.8 | 99 | YES | YES |
CVE-2025-32429CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's p | Jul 24, 2025 | 9.8 | 90 | NO | YES |
CVE-2024-21650CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its use | Jan 8, 2024 | 9.8 | 83 | NO | YES |
CVE-2025-32969CRITICAL XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL | Apr 23, 2025 | 9.8 | 81 | NO | YES |
CVE-2023-37462HIGH XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an i | Jul 14, 2023 | 8.8 | 80 | NO | YES |
CVE-2023-46731CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the | Nov 6, 2023 | 9.8 | 78 | NO | NO |
CVE-2023-50719HIGH XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password | Dec 15, 2023 | 7.5 | 75 | NO | YES |
CVE-2023-48241HIGH XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that a | Nov 20, 2023 | 7.5 | 73 | NO | YES |
CVE-2023-35150HIGH XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0 | Jun 23, 2023 | 8.0 | 70 | NO | NO |
CVE-2023-26477CRITICAL XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macro | Mar 2, 2023 | 9.8 | 70 | NO | NO |
Signals from CVEs in this vendor scope (282 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xwiki.
Media articles that mention a CVE ID that affects a product developed by Xwiki — matched by CVE ID, not by vendor name.