GHSA-rj7p-xjv7-7229 · Severity: critical · Ecosystem: maven — XWiki Remote Code Execution Vulnerability via User Registration
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.
Conclusion & alert: CVE-2024-21650 is rated High Exploit Risk (89.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 92.54%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-15 | 92.68% | 92.54% | -0.14% |
| 2 | 2026-03-04 | 93.34% | 92.68% | -0.66% |
| 3 | 2026-03-03 | — | 93.34% | — |
Full EPSS history (56 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 3.1 | CRITICAL |
|
3.9 | 6.0 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-rj7p-xjv7-7229 · Severity: critical · Ecosystem: maven — XWiki Remote Code Execution Vulnerability via User Registration
| URL | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/b290bfd573c6f7db6cc15a88dd4111d9fcad0d31 | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rj7p-xjv7-7229 | Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-21173 | Exploit Issue Tracking Vendor Advisory |