CVE 8.3 HIGH

XWiki Remote Macros vulnerable to remote code execution using the confluence details summary macro_CVE-2025-65036

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Description

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.

Basic Information

ID CVE-2025-65036
Source GitHub_M
Published Dec 5, 2025 at 16:10
Modified Dec 5, 2025 at 16:27

Affected Product

Vendor xwikisas
Product xwiki-pro-macros
Version < 1.27.1
Affected Versions xwikisas xwiki-pro-macros < 1.27.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.