GHSA-6mjp-2rm6-9g85 · Severity: critical · Ecosystem: maven — XWiki CKEditor.HTMLConverter vulnerable to Remote Code Execution via Cross-Site Request Forgery
CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. If a privileged user with programming rights was tricked into executing a GET request to this document with certain parameters (e.g., via an image with a corresponding URL embedded in a comment or via a redirect), this would allow arbitrary remote code execution and the attacker could gain rights, access private information or impact the availability of the wiki. The issue has been patched in the CKEditor Integration version 1.64.3. This has also been patched in the version of the CKEditor integration that is bundled starting with XWiki 14.6 RC1. There are no known workarounds for this other than upgrading the CKEditor integration to a fixed version.
Conclusion & alert: CVE-2023-22457 is rated High Exploit Risk (89.9/100): CVSS Critical severity, with high exploitation likelihood (EPSS 18.73%, 97th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +17.60% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.13% | 18.73% | +17.60% |
| 2 | 2026-01-19 | 2.17% | 1.13% | -1.04% |
| 3 | 2026-01-12 | — | 2.17% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
GHSA-6mjp-2rm6-9g85 · Severity: critical · Ecosystem: maven — XWiki CKEditor.HTMLConverter vulnerable to Remote Code Execution via Cross-Site Request Forgery
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2023-22457 medium priority: Ubuntu including 4 source packages (ckeditor, ckeditor3, ldap-account-manager, request-tracker4), 52 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 31, needs-triage 12, not-affected 8, DNE 1. | https://ubuntu.com/security/CVE-2023-22457 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| xwiki | ckeditor_integration | < 1.64.3 | cpe:2.3:a:xwiki:ckeditor_integration:*:*:*:*:*:xwiki:*:* |
| URL | Tags |
|---|---|
| https://github.com/xwiki-contrib/application-ckeditor/commit/6b1053164386aefc526df7512bc664918aa6849b | Patch Third Party Advisory |
| https://github.com/xwiki-contrib/application-ckeditor/security/advisories/GHSA-6mjp-2rm6-9g85 | Exploit Patch Third Party Advisory |
| https://jira.xwiki.org/browse/CKEDITOR-475 | Exploit Issue Tracking Patch Vendor Advisory |