PT-2025-25432 · Xwiki · Xwiki

Michael Hamann

·

Published

2025-06-13

·

Updated

2025-09-03

·

CVE-2025-49581

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 16.4.7 XWiki versions prior to 16.10.3 XWiki versions prior to 17.0.0
Description The issue allows any user with edit rights on a page to execute code, including Groovy, Python, and Velocity, with programming rights by defining a wiki macro. This can grant full access to the whole XWiki installation. The problem arises when a wiki macro parameter allows wiki syntax, and its default value is executed with the rights of the author of the document where it is used. This can be exploited by overriding a macro, such as the children macro, allowing arbitrary script macros.
Recommendations For versions prior to 16.4.7, update to version 16.4.7 or later to enforce proper rights management. For versions prior to 16.10.3, update to version 16.10.3 or later to enforce proper rights management. For versions prior to 17.0.0, update to version 17.0.0 or later to enforce proper rights management.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-13441
CVE-2025-49581
GHSA-9875-CW22-F7CX

Affected Products

Xwiki