CVE Database
/

CVE-2026-33229

Back to search

CVE-2026-33229

Published: Apr 8, 2026

Modified: Apr 10, 2026

PUBLISHED

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1.

VendorProductVersions

xwiki

xwiki-platform

affected
>= 17.0.0-rc-1, < 17.4.8
affected
>= 17.5.0-rc-1, < 17.10.1

org.xwiki.platform

xwiki-platform-legacy-oldcore

affected
>= 17.0.0-rc-1, < 17.4.8
affected
>= 17.5.0-rc-1, < 17.10.1

org.xwiki.platform

xwiki-platform-oldcore

affected
>= 17.0.0-rc-1, < 17.4.8
affected
>= 17.5.0-rc-1, < 17.10.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now