CVE-2023-29506
XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.
- Affected products
- Xwiki
- Xwiki
- < 13.10.11, 14.4.7, 14.6, 14.10
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2023-04-16
CVE-2023-29506 at NVD
No indexed exploits for CVE-2023-29506 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-29506 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.