Critical severity9.9NVD Advisory· Published Mar 2, 2023· Updated Jun 17, 2026
CVE-2023-26474
CVE-2023-26474
Description
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.xwiki.platform:xwiki-platform-oldcoreMaven | >= 13.10, < 13.10.11 | 13.10.11 |
org.xwiki.platform:xwiki-platform-legacy-oldcoreMaven | >= 13.10, < 13.10.11 | 13.10.11 |
org.xwiki.platform:xwiki-platform-oldcoreMaven | >= 14.0, < 14.4.7 | 14.4.7 |
org.xwiki.platform:xwiki-platform-legacy-oldcoreMaven | >= 14.0, < 14.4.7 | 14.4.7 |
org.xwiki.platform:xwiki-platform-oldcoreMaven | >= 14.5, < 14.10 | 14.10 |
org.xwiki.platform:xwiki-platform-legacy-oldcoreMaven | >= 14.5, < 14.10 | 14.10 |
Affected products
4- ghsa-coords2 versionspkg:maven/org.xwiki.platform/xwiki-platform-legacy-oldcorepkg:maven/org.xwiki.platform/xwiki-platform-oldcore
>= 13.10, < 13.10.11+ 1 more
- (no CPE)range: >= 13.10, < 13.10.11
- (no CPE)range: >= 13.10, < 13.10.11
- Range: >= 13.10, < 13.10.11
Patches
Vulnerability mechanics
References
4- github.com/xwiki/xwiki-platform/security/advisories/GHSA-3738-p9x3-mv9rnvdExploitVendor AdvisoryWEB
- jira.xwiki.org/browse/XWIKI-20373nvdExploitIssue TrackingPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-3738-p9x3-mv9rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26474ghsaADVISORY
News mentions
0No linked articles in our index yet.