216.73.217.22

CVE-2025-53835

· Published 14/07/2025 23:15 · Modified 15/07/2025 20:15

Labels: CVE-2025-53835 2025-07-14CVE-2025-53835CWE-79[email protected]

Essential information

Published
14/07/2025 23:15
Modified
15/07/2025 20:15
Author
Creator
CVSS
9.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 and prior to version 14.10, the XHTML syntax depended on the `xdom+xml/current` syntax which allows the creation of raw blocks that permit the insertion of arbitrary HTML content including JavaScript. This allows XSS attacks for users who can edit a document like their user profile (enabled by default). This has been fixed in version 14.10 by removing the dependency on the `xdom+xml/current` syntax from the XHTML syntax. Note that the `xdom+xml` syntax is still vulnerable to this attack. As it's main purpose is testing and its use is quite difficult, this syntax shouldn't be installed or used on a regular wiki. There are no known workarounds apart from upgrading.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
xwiki / xwiki rendering cpe:2.3:a:xwiki:xwiki_rendering:5.4.5:*:*:*:*:*:*:*
xwiki / xwiki rendering cpe:2.3:a:xwiki:xwiki_rendering:<14.10:*:*:*:*:*:*:*

References