PT-2025-36929 · Xwiki · Xwiki Remote Macros

·

CVE-2025-55729

·

Published

2025-09-09

·

Updated

2025-09-10

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: XWiki Remote Macros versions 1.0 through 1.26.5
Description: XWiki Remote Macros provides XWiki rendering macros used for migrating content from Confluence. A missing escaping mechanism in the ac:type parameter within the ConfluenceLayoutSection macro allows for remote code execution. The classes parameter is used without proper escaping in XWiki syntax, enabling XWiki syntax injection, which also leads to remote code execution.
Recommendations: Update to version 1.26.5 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55729
GHSA-22XJ-JPJG-GPGW

Affected Products

Xwiki Remote Macros