PT-2025-49257 · Xwiki · Xwiki Remote Macros

CVE-2025-65036

·

Published

2025-12-05

·

Updated

2026-02-20

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions XWiki Remote Macros versions prior to 1.27.1
Description The software includes XWiki rendering macros designed for content migration from Confluence. Prior to version 1.27.1, the macro executes Velocity code from details pages without proper permission checks. This can potentially allow for remote code execution.
Recommendations Update to version 1.27.1 or later.

Exploit

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65036
GHSA-472X-FWH9-R82F

Affected Products

Xwiki Remote Macros