Remote Code Execution Vulnerability in XWiki Remote Macros by XWiki
CVE-2025-65036
8.3HIGH
What is CVE-2025-65036?
The XWiki Remote Macros component allows for the execution of Velocity scripts without proper permissions validation prior to version 1.27.1. This design flaw can be exploited to execute arbitrary code remotely, potentially leading to unauthorized system access. The issue has been rectified in version 1.27.1, where permissions checks have been implemented to enhance security.
Affected Version(s)
xwiki-pro-macros < 1.27.1
