PT-2026-95407 · Xwiki · Xwiki

CVE-2025-53837

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 14.10.2 XWiki versions prior to 15.0 RC1
Description XWiki Rendering, a system that converts textual input from one syntax to another, fails to properly escape rendering output when it is included as content within HTML macros. This allows a user with permissions to edit their own profile or any other document to close the HTML macro and inject arbitrary script macros, such as Groovy and Python. This can lead to remote code execution and unrestricted read and write access to all wiki contents. The issue can be triggered by adding an object of type XWiki.UIExtensionClass to a document with specific content and configuring the extension point id as org.xwiki.platform.html.head.
Recommendations Update to version 14.10.2. Update to version 15.0 RC1.

Exploit

Fix

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53837
GHSA-26VP-8GXG-V4PG

Affected Products

Xwiki