PT-2025-49257 · Xwiki · Xwiki Remote Macros

Published

2025-12-05

·

Updated

2026-02-20

·

CVE-2025-65036

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions XWiki Remote Macros versions prior to 1.27.1
Description The software includes XWiki rendering macros designed for content migration from Confluence. Prior to version 1.27.1, the macro executes Velocity code from details pages without proper permission checks. This can potentially allow for remote code execution.
Recommendations Update to version 1.27.1 or later.

Exploit

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-65036
GHSA-472X-FWH9-R82F

Affected Products

Xwiki Remote Macros