XWiki Rendering Vulnerability in XWiki Product
CVE-2025-53836 
What is CVE-2025-53836?
The vulnerability in the XWiki Rendering component allows for unauthorized execution of macros in restricted mode due to a flaw in the default macro content parser. In certain versions of XWiki, this flaw enables executing prohibited macros, notably script macros, potentially leading to script execution vulnerabilities. This risk is particularly concerning when untrusted users are involved, as they could gain access to functionalities that should typically be restricted. Users are advised to disable comment functionality for untrusted users until the system is upgraded to patched versions (13.10.11, 14.4.7, or 14.10) that rectify this issue.
Affected Version(s)
xwiki-rendering >= 4.2-milestone-1, < 13.10.11 < 4.2-milestone-1, 13.10.11
xwiki-rendering >= 14.0, < 14.4.7 < 14.0, 14.4.7
xwiki-rendering >= 14.5, < 14.10 < 14.5, 14.10