Cross-site scripting in XWiki platform - CVE-2023-29202
Published: April 12, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to execute arbitrary actions in the wiki.
The vulnerability exists due to cross-site scripting in the RSS macro HTML output when rendering feed item content from an attacker-controlled RSS feed with the content parameter set to true. A remote user can specify a malicious RSS feed to execute arbitrary actions in the wiki.
User interaction is required, and exploitation becomes particularly severe if a user with programming rights views the page.