XWiki Rendering Remote Code Execution Vulnerability in XWiki Products
CVE-2025-53837

9.9CRITICAL

Key Information:

Vendor

Xwiki

Vendor
CVE Published:
18 September 2026

What is CVE-2025-53837?

The XWiki Rendering system is vulnerable due to improper handling of rendering output in HTML macros, allowing unauthorized users to execute arbitrary script macros, including Groovy and Python. This leads to potential remote code execution and unrestricted access to all content within the wiki. Updates in versions 14.10.2 and 15.0 RC1 have implemented measures to prevent the closing of HTML macros by rendering output, thus mitigating this risk. Users are advised to update promptly to secure their installations.

Affected Version(s)

xwiki-rendering < 14.10.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.