Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2025-53837: XWiki Rendering lets attackers run scripts via profile edit

CVE-2025-53837 · published 22 days ago
Summary

Versions of XWiki Rendering before 14.10.2 and 15.0 RC1 let anyone who can edit their own profile or a document insert code that runs on the server, potentially reading or changing any wiki content. The problem is caused by unescaped output that can close an HTML block and inject script macros. Updating to XWiki Rendering 14.10.2 or later removes the issue; apply the update as soon as possible.

What to do
  • Update xwiki org.xwiki.rendering:xwiki-rendering-xml to version 14.10.2.
  • Update org.xwiki.rendering:xwiki-rendering-xml to version 14.10.2.
Affected software
Ecosystem VendorProductAffected versions
– xwiki xwiki-rendering < 14.10.2
maven xwiki org.xwiki.rendering:xwiki-rendering-xml < 14.10.2
Fix: upgrade to 14.10.2
maven – org.xwiki.rendering:xwiki-rendering-xml < 14.10.2
Fix: upgrade to 14.10.2
Original advisory text
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published18 Sep 2026
Updated9 Oct 2026
First seen18 Sep 2026
Track software like this
Free during beta