Cross-site request forgery in XWiki platform - CVE-2022-36095
Published: September 8, 2022 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote attacker to modify tags on XWiki pages.
The vulnerability exists due to cross-site request forgery (CSRF) in documentTags.vm when handling requests to add or remove tags. A remote attacker can trick a victim into sending a crafted request to modify tags on XWiki pages.
User interaction is required.