GHSA-35j5-m29r-xfq5 · Severity: high · Ecosystem: maven — XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro
XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-macro-footnotes` and prior to version 15.1-rc-1 of `org.xwiki.platform:xwiki-rendering-macro-footnotes`, the footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.6 and 15.1-rc-1. There is no workaround apart from upgrading to a fixed version of the footnote macro.
Conclusion & alert: CVE-2023-37912 is rated High Exploit Risk (82/100): CVSS Critical severity, with high exploitation likelihood (EPSS 9.89%, 93th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 28.58% | 9.89% | -18.69% |
| 2 | 2025-11-18 | 9.89% | 28.58% | +18.69% |
| 3 | 2025-04-15 | — | 9.89% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
GHSA-35j5-m29r-xfq5 · Severity: high · Ecosystem: maven — XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| xwiki | xwiki-rendering | < 14.10.6 | cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:* |
| xwiki | xwiki-rendering | 15.0 | cpe:2.3:a:xwiki:xwiki-rendering:15.0:rc1:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e | Patch |
| https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-35j5-m29r-xfq5 | Patch Vendor Advisory |
| https://jira.xwiki.org/browse/XRENDERING-688 | Exploit Issue Tracking Patch Vendor Advisory |