Back to Database
Status published
Critical
CVE-2020-11057
Code Injection in XWiki Platform
Vulnerability Description
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-11057
Credits & Attribution
No credits recorded in the NVD database.
References
More from xwiki
View All →CVE-2025-66474
XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection
High
8.7
CVE-2025-66473
XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikis
High
8.7
CVE-2025-66472
XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication
Medium
6.5
CVE-2025-58049
XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
Medium
5.8
CVE-2025-55749
The XWiki Jetty package (XJetty) allows accessing any application file through URL
High
8.7
Affected Vendor
xwiki
View all reports →Affected Software
XWiki Platform
Vulnerable Versions:
>= 7.2, < 11.10.3
Timeline
Official Publish:
May 12th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L