Remote Code Execution Vulnerability in XWiki Rendering Macros by XWiki
CVE-2025-55727

10CRITICAL

Key Information:

Vendor

Xwikisas

Vendor
CVE Published:
9 September 2025

What is CVE-2025-55727?

The XWiki Remote Macros component has a vulnerability due to the lack of proper escaping of the width parameter within the column macro. This oversight affects users who can edit any page or those accessing the CKEditor converter, enabling them to exploit XWiki syntax injection. Specifically, an attacker with programming rights or admin access could execute arbitrary Velocity code. This issue persists in versions 1.0 through 1.26.4 but has been resolved in version 1.26.5 with a security patch.

Affected Version(s)

xwiki-pro-macros >= 1.0, < 1.26.5

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55727 : Remote Code Execution Vulnerability in XWiki Rendering Macros by XWiki