
CVE-2026-33229 - Notes - https://youssefazefzaf.com/posts/cve
Post summary
The content only references CVE-2026-33229 with a generic notes link, offering no additional details.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-04-08 | 4 | Disclosure4 |
| 2026-04-11 | 1 | General1 |

CVE-2026-33229 - Notes - https://youssefazefzaf.com/posts/cve
Post summary
The content only references CVE-2026-33229 with a generic notes link, offering no additional details.

XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API CVE: CVE-2026-33229 PT-Identifier: PT-2026-31324 Vendor: Xwiki Product: xwiki-platform CVSS: 8.6 Credits: n/a Description: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-33229 • https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h259-74h5-4rh9 • https://github.com/xwiki/xwiki-platform/commit/9fe84da66184c05953df9466cf3a4acd15a46e63 • https://jira.xwiki.org/browse/XWIKI-23698 • https://jira.xwiki.org/browse/XWIKI-23702 #dbugs_vuln
Post summary
The vulnerability CVE-2026-33229 in XWiki allows arbitrary Python execution for users with script rights; it is patched in newer releases with no reported active exploitation or PoC disclosed.

🚨*CVE* CVE-2026-33229 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scriptin… https://www.cve.org/CVERecord?id=CVE-2026-33229 ----- Traducción: CVE-2026-33229 XWi… http://infoflow.cloud`
Post summary
The tweet simply announces CVE-2026-33229 with a brief description and version references, serving as a disclosure notice without detailed technical or exploit information.

CVE-2026-33229 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scriptin… https://www.cve.org/CVERecord?id=CVE-2026-33229
Post summary
The text announces CVE-2026-33229 against XWiki Platform before versions 17.4.8 and 17.10.1, noting an improperly protected script issue, but provides no PoC, exploit, patch, or further technical detail.

CVE-2026-33229 Arbitrary Code Execution in XWiki Platform Prior to 17.4.8 and 17.10.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33229
Post summary
A new CVE (CVE‑2026‑33229) for arbitrary code execution in XWiki Platform versions before 17.4.8 and 17.10.1 is listed, but no proof‑of‑concept, exploit tool, active exploitation, or patch details are provided.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | xwiki | xwiki | - | - | - |