CRITICAL 9.9 CVE-2025-53837 Published 18 Sept 2026

XWiki Remote Code Execution via Script Macros

Worried this affects your website?

XWiki's Rendering system, prior to versions 14.10.2 and 15.0 RC1, allows users with edit permissions to execute arbitrary script macros, including Groovy and Python, leading to remote code execution and unrestricted read/write access to wiki contents.

This is due to rendering output being included in HTML macros without proper escaping, allowing users to inject and execute script macros with programming rights.

XWiki has patched this issue in versions 14.10.2 and 15.0 RC1 by ensuring rendering output cannot close the surrounding HTML macro.

While a workaround is available, it requires adding escaping to all places where rendering output is used in wiki documents, but a comprehensive list is not yet available.

Reference: CVE-2025-53837 on NVD

← Back to Security News