boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-24893

xwiki xwiki-platform — Remote code execution as guest via SolrSearchMacros request in xwiki
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9986   100.0   YES
AFFECTED
  Product         Versions                          Fixed
  xwiki-platform  >= 5.3-milestone-2, < 15.10.11 –  —
TIMELINE
  Jan 27  Reserved by GitHub_M
  Feb 20  Published (CNA: GitHub_M)
  Oct 30  Added to CISA KEV, remediation due 2025-11-20
CWE-95 · CNA: GitHub_M · CVSS v3.1 · 6 references · KEV due November 20, 2025

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 27, 2025ReservedReserved by GitHub_M
February 20, 2025PublishedPublished (CNA: GitHub_M)
October 30, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-11-20

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
xwikixwiki-platform—>= 5.3-milestone-2, < 15.10.11—

Weaknesses

CWE-95

References (6)

Related

Authoritative record: CVE-2025-24893 at cve.org

Vendors: xwiki

Weaknesses: CWE-95

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-24893 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.