PT-2025-36930 · Xwiki · Xwiki Remote Macros

Farcasut

·

Published

2025-09-09

·

Updated

2025-09-10

·

CVE-2025-55730

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: XWiki Remote Macros versions 1.0 through 1.26.5
Description: XWiki Remote Macros provides XWiki rendering macros used for migrating content from Confluence. A missing escaping mechanism in the confluence paste code macro allows for remote code execution for users with page editing permissions. The classes parameter is used without proper escaping, leading to XWiki syntax injection, which can enable remote code execution.
Recommendations: Update to version 1.26.5 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2025-55730
GHSA-5W8V-H22G-J2MP

Affected Products

Xwiki Remote Macros