Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HSummary
CVE-2024-31465 is a critical-severity Eval Injection (CWE-95) vulnerability in Xwiki Xwiki. Its CVSS base score is 9.9 (Critical).
Operationally, ranked in the top 0.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
XWiki Platform, a generic wiki platform, contains a remote code execution vulnerability affecting versions from 5.0-rc-1 through 14.10.19, 15.5.3, and 15.9-rc-0. The flaw stems from improper handling of objects of type XWiki.SearchSuggestSourceClass, which permits server-side code execution when such an object is added to a page. It is tracked as CVE-2024-31465 with a CVSS score of 9.9 and is associated with CWE-94 and CWE-95.
Any authenticated user holding edit rights on at least one page can exploit the issue by inserting the malicious object into their own user profile or another accessible document. Successful exploitation grants arbitrary code execution on the server, allowing full compromise of the confidentiality, integrity, and availability of the XWiki installation.
The vulnerability was addressed in the releases 14.10.20, 15.5.4, and 15.10-rc-1. Official guidance recommends upgrading to one of these versions; a workaround consists of manually applying the patch to the document XWiki.SearchSuggestSourceSheet. The referenced GitHub commits and security advisory GHSA-34fj-r5gq-7395 contain the detailed changes.
The EPSS score has remained at 0.3531 with no material increase since disclosure.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-1075
Vulnerability Data
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type…
more
`XWiki.SearchSuggestSourceClass` to their user profile or any other page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10 RC1. As a workaround, manually apply the patch to the document `XWiki.SearchSuggestSourceSheet`.
- CWE(s)
Related Threats
Likely ATT&CK TechniquesAI
Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Enforces that edit rights on a page cannot be used to insert XWiki.SearchSuggestSourceClass objects that trigger server-side code execution.
Restricts the privileges granted to any authenticated user so that page-edit capability cannot be abused for arbitrary code execution on the host.
Validates or sanitizes objects of type XWiki.SearchSuggestSourceClass before they are persisted, blocking the code-injection path described in the CVE.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require input neutralization and avoidance of unsafe dynamic evaluation.
PR.DS-10 protects runtime data confidentiality/integrity but has no bearing on neutralizing externally influenced input during code generation, so neither direction shows any preventive effect.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect eval injection vulnerabilities before deployment.
Secure development life cycle mandates input validation and safe coding practices that directly prevent eval injection.
Application security requirements include rules against dynamic code execution of untrusted input.
Secure architecture principles discourage unsafe dynamic evaluation constructs.
Secure coding explicitly requires neutralization of input before dynamic evaluation, directly mitigating eval injection.
Separation of environments limits the blast radius if eval injection occurs in non-production.