Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-24893
xwiki xwiki-platform — Remote code execution as guest via SolrSearchMacros request in xwiki
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .9986 100.0 YES
AFFECTED
Product Versions Fixed
xwiki-platform >= 5.3-milestone-2, < 15.10.11 – —
TIMELINE
Jan 27 Reserved by GitHub_M
Feb 20 Published (CNA: GitHub_M)
Oct 30 Added to CISA KEV, remediation due 2025-11-20
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 27, 2025 | Reserved | Reserved by GitHub_M |
| February 20, 2025 | Published | Published (CNA: GitHub_M) |
| October 30, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2025-11-20 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| xwiki | xwiki-platform | — | >= 5.3-milestone-2, < 15.10.11 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-24893 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.