# Affected Range Starting After 6.3

CVEs with an affected range that starts after version 6.3 (exclusive).

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/enrichment-cpe-version-start-excluding/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs with an affected range that starts after version 6.3 (exclusive).

Example 7 of 14 in **Filters › Affected Products (CPE)** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `enrichment.cpe.version_start_excluding` · `operator` `eq`

`enrichment.cpe.version_start_excluding` is the version after which the affected range starts (exclusive).

`eq` matches the exact value `6.3`.

In the response, look at `results[].enrichment.cpe[].version_start_excluding`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `enrichment.cpe.version_start_excluding` |
| `filters.must[0].type` | body | `eq` |
| `filters.must[0].value` | body | `6.3` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "enrichment.cpe.version_start_excluding",
        "type": "eq",
        "value": "6.3"
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results[].enrichment.cwe[].capec_id: first 10 items

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 1,
  "results": [
    {
      "id": "CVE-2023-27479",
      "source_identifier": "user@github.com",
      "published": "2023-03-07T19:15:12Z",
      "last_modified": "2026-06-17T05:45:17Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of UIX parameters. A proof of concept exploit is to log in, add an `XWiki.UIExtensionClass` xobject to the user profile page, with an Extension Parameters content containing `label={{/html}} {{async async=\"true\" cached=\"false\" context=\"doc.reference\"}}{{groovy}}println(\"Hello \" + \"from groovy!\"){{/groovy}}{{/async}}`. Then, navigating to `PanelsCode.ApplicationsPanelConfigurationSheet` (i.e., `<xwiki-host>/xwiki/bin/view/PanelsCode/ApplicationsPanelConfigurationSheet` where `<xwiki-host>` is the URL of your XWiki installation) should not execute the Groovy script. If it does, you will see `Hello from groovy!` displayed on the screen. This vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10-rc-1. Users are advised to upgrade. For users unable to upgrade the issue can be fixed by editing the `PanelsCode.ApplicationsPanelConfigurationSheet` wiki page and making the same modifications  as shown in commit `6de5442f3c`."
        }
      ],
      "references": [
        {
          "url": "https://github.com/xwiki/xwiki-platform/commit/6de5442f3c91c3634a66c7b458d5b142e1c2a2dc",
          "source": "user@github.com",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qxjg-jhgw-qhrv",
          "source": "user@github.com",
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://jira.xwiki.org/browse/XWIKI-20294",
          "source": "user@github.com",
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://github.com/xwiki/xwiki-platform/commit/6de5442f3c91c3634a66c7b458d5b142e1c2a2dc",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qxjg-jhgw-qhrv",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://jira.xwiki.org/browse/XWIKI-20294",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@github.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "LOW",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.9,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.1,
            "impact_score": 6.0
          },
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "LOW",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.9,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.1,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@github.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-74"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "DD6E852A-AEF3-4202-94F3-35D01894F6F8",
                  "version_start_including": null,
                  "version_start_excluding": "6.3",
                  "version_end_including": null,
                  "version_end_excluding": "13.10.11"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "FA3A5151-58FB-48CF-BFFB-5688608200C8",
                  "version_start_including": "14.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "14.4.7"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "569EE28C-5C86-467F-A153-DD4B9BF0053D",
                  "version_start_including": "14.5",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "14.10"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:xwiki:xwiki:6.3:-:*:*:*:*:*:*",
                  "match_criteria_id": "939A1216-3065-4637-B747-CE8A5E194EEE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:xwiki:xwiki:6.3:milestone1:*:*:*:*:*:*",
                  "match_criteria_id": "66AA1260-807B-4ED6-99D0-28C869A49D75",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:xwiki:xwiki:6.3:milestone2:*:*:*:*:*:*",
                  "match_criteria_id": "6387A0C9-03A5-43B5-81CB-034A745FF4A0",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
            "vendor": "xwiki",
            "product": "xwiki",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": "6.3",
            "version_end_including": null,
            "version_end_excluding": "13.10.11",
            "affected_versions_first": "6.4",
            "affected_versions_last": "13.10.10"
          },
          {
            "criteria": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
            "vendor": "xwiki",
            "product": "xwiki",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "14.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "14.4.7",
            "affected_versions_first": "14.0",
            "affected_versions_last": "14.4.6"
          },
          {
            "criteria": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
            "vendor": "xwiki",
            "product": "xwiki",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "14.5",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "14.10",
            "affected_versions_first": "14.5.0",
            "affected_versions_last": "14.9"
          },
          {
            "criteria": "cpe:2.3:a:xwiki:xwiki:6.3:-:*:*:*:*:*:*",
            "vendor": "xwiki",
            "product": "xwiki",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "6.3",
            "affected_versions_last": "6.3"
          },
          {
            "criteria": "cpe:2.3:a:xwiki:xwiki:6.3:milestone1:*:*:*:*:*:*",
            "vendor": "xwiki",
            "product": "xwiki",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "6.3",
            "affected_versions_last": "6.3"
          },
          {
            "criteria": "cpe:2.3:a:xwiki:xwiki:6.3:milestone2:*:*:*:*:*:*",
            "vendor": "xwiki",
            "product": "xwiki",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "6.3",
            "affected_versions_last": "6.3"
          }
        ],
        "cwe": [
          {
            "id": 74,
            "owasptop10_2021": "A03 Injection",
            "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
            "description": "The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.",
            "capec_id": [
              3,
              6,
              7,
              8,
              9,
              10,
              13,
              14,
              24,
              28
            ],
            "scope": [
              "Access Control",
              "Confidentiality",
              "Integrity",
              "Non-Repudiation",
              "Other"
            ],
            "impact": [
              "Alter Execution Logic",
              "Bypass Protection Mechanism",
              "Hide Activities",
              "Other",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.01144,
          "percentile": 0.65336,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "LOW",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.9,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [Affected Range Starting at 12.5.0](/reference/vulnerability/search/examples/enrichment-cpe-version-start-including/)
- [Affected Range Ending at 2.4.2](/reference/vulnerability/search/examples/enrichment-cpe-version-end-including/)
- [Affected Products That Are Platforms](/reference/vulnerability/search/examples/enrichment-cpe-vulnerable/)
- [Affected Range Fixed in 19.1.8](/reference/vulnerability/search/examples/enrichment-cpe-version-end-excluding/)
- [Affected Hardware](/reference/vulnerability/search/examples/enrichment-cpe-product-type/)
- [First Affected Release 2023.4](/reference/vulnerability/search/examples/enrichment-cpe-affected-versions-first/)
