Remote Code Execution Vulnerability in XWiki Rendering Macros by XWiki
CVE-2025-55727
10CRITICAL
What is CVE-2025-55727?
The XWiki Remote Macros component has a vulnerability due to the lack of proper escaping of the width parameter within the column macro. This oversight affects users who can edit any page or those accessing the CKEditor converter, enabling them to exploit XWiki syntax injection. Specifically, an attacker with programming rights or admin access could execute arbitrary Velocity code. This issue persists in versions 1.0 through 1.26.4 but has been resolved in version 1.26.5 with a security patch.
Affected Version(s)
xwiki-pro-macros >= 1.0, < 1.26.5