Back to overview

CVE-2025-55727

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code execution for any user who can edit any page or who can access the CKEditor converter. The width parameter is used without escaping in XWiki syntax, thus allowing XWiki syntax injection which enables remote code execution when the macro has been installed by a user with programming right, or it at least allows executing Velocity code as the wiki admin. Version 1.26.5 contains a patch for the issue.

Metadata

CVE ID
CVE-2025-55727
State
PUBLISHED
Assigner
GitHub_M
Reserved
2025-08-14 22:31 UTC
Published
2025-09-09 18:31 UTC
Last updated
2025-09-10 14:14 UTC
Primary CWE
CWE-95
CWE-95: Improper Neutralization of Directives in Dynamically…
Vendor / Product
xwikisas / xwiki-pro-macros
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
xwikisas xwiki-pro-macros >= 1.0, < 1.26.5
Weakness (CWE)
CWESourceDescription
CWE-95 cna CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
References (3)
Back to overview