216.73.216.226

CVE-2025-66474

· Published 10/12/2025 22:16 · Modified 19/12/2025 17:13

Labels: CVE-2025-66474 2025-12-10CVE-2025-66474CWE-94CWE-95[email protected]

Essential information

Published
10/12/2025 22:16
Modified
19/12/2025 17:13
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, which attackers can exploit through RCE. Any user who can edit their own profile or any other document can execute arbitrary script macros, including Groovy and Python macros, which enable remote code execution as well as unrestricted read and write access to all wiki contents. This issue is fixed in versions 16.10.10, 17.4.3 and 17.6.0-rc-1.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
xwiki / xwiki-rendering cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:*
xwiki / xwiki-rendering cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:*
xwiki / xwiki-rendering cpe:2.3:a:xwiki:xwiki-rendering:17.5.0:-:*:*:*:*:*:*
xwiki / xwiki-rendering cpe:2.3:a:xwiki:xwiki-rendering:17.5.0:rc1:*:*:*:*:*:*

References