CVE-2025-53837Critical· 9.9▾ MidnightXWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile o…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
Last analysed / modified upstream
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
org.xwiki.rendering:xwiki-rendering-xml < 14.10.2Patched in:
org.xwiki.rendering:xwiki-rendering-xml 14.10.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44179Critical· 9.9xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
CVE-2026-53966High· 7.1XWiki Platform is a generic wiki platform
CVE-2026-34151High· 8.2XWiki Platform is a generic wiki platform
CVE-2023-37465Medium· 6.5org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
CVE-2026-63325High· 7.8Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier
CVE-2026-19780High· 8.8Koha Eval Code Injection Remote Code Execution Vulnerability