---
id: CVE-2025-65036
title: >-
  XWiki Remote Macros provides XWiki rendering macros that are useful when
  migrating content from Confluence
summary: >-
  XWiki Remote Macros provides XWiki rendering macros that are useful when
  migrating content from Confluence. Prior to 1.27.1, the macro executes
  Velocity from the details pages without checking for permissions, which can
  lead to remote co…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-862
vendor: xwiki
product: pro_macros
affected:
  - pro_macros < 1.27.1
patched:
  - pro_macros 1.27.1
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65036'
references:
  - url: >-
      https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-472x-fwh9-r82f
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00397
epssPercentile: 0.31196
ingestedAt: '2026-09-25T23:21:16.895Z'
---

## Overview

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.

## Affected

- `pro_macros < 1.27.1`

## Remediation

Upgrade past the affected range:

- `pro_macros 1.27.1`
