Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2025-53837: XWiki Rendering lets attackers run scripts via profile edit
CVE-2025-53837 · published 22 days ago
Summary
Versions of XWiki Rendering before 14.10.2 and 15.0 RC1 let anyone who can edit their own profile or a document insert code that runs on the server, potentially reading or changing any wiki content. The problem is caused by unescaped output that can close an HTML block and inject script macros. Updating to XWiki Rendering 14.10.2 or later removes the issue; apply the update as soon as possible.
What to do
- Update xwiki org.xwiki.rendering:xwiki-rendering-xml to version 14.10.2.
- Update org.xwiki.rendering:xwiki-rendering-xml to version 14.10.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | xwiki | xwiki-rendering | < 14.10.2 |
| maven | xwiki | org.xwiki.rendering:xwiki-rendering-xml |
< 14.10.2 Fix: upgrade to 14.10.2
|
| maven | – | org.xwiki.rendering:xwiki-rendering-xml |
< 14.10.2 Fix: upgrade to 14.10.2
|
Original advisory text
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.
References
- https://jira.xwiki.org/browse/XRENDERING-693
- https://github.com/advisories/GHSA-26vp-8gxg-v4pg
- https://github.com/xwiki/xwiki-rendering/commit/92bc8095ed3acce15ab200c8525e1623...
- https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-26vp-8gxg-v4pg
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53837... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-53837 Vendor Advisory
- https://github.com/xwiki/xwiki-rendering/releases/tag/xwiki-rendering-14.10.2
- https://github.com/xwiki/xwiki-rendering/releases/tag/xwiki-rendering-15.0-rc-1
- https://jira.xwiki.org/browse/XWIKI-20313
- https://jira.xwiki.org/browse/XWIKI-20327
- https://github.com/xwiki/xwiki-rendering Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published18 Sep 2026
Updated9 Oct 2026
First seen18 Sep 2026
Sources
CVE-2025-53837 · NVD
CVE-2025-53837 · MITRE
GHSA-26vp-8gxg-v4pg · GHSA
CVE-2025-53837 · OSV
GHSA-26vp-8gxg-v4pg · OSV
Track software like this
Free during beta