PT-2026-95407 · Xwiki · Xwiki
CVE-2025-53837
·
Published
2026-09-17
·
Updated
2026-09-18
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki versions prior to 14.10.2
XWiki versions prior to 15.0 RC1
Description
XWiki Rendering, a system that converts textual input from one syntax to another, fails to properly escape rendering output when it is included as content within HTML macros. This allows a user with permissions to edit their own profile or any other document to close the HTML macro and inject arbitrary script macros, such as Groovy and Python. This can lead to remote code execution and unrestricted read and write access to all wiki contents. The issue can be triggered by adding an object of type
XWiki.UIExtensionClass to a document with specific content and configuring the extension point id as org.xwiki.platform.html.head.Recommendations
Update to version 14.10.2.
Update to version 15.0 RC1.
Exploit
Fix
RCE
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki