CVE Feed

    Dashboard / CVE / CVE-2025-24893

    CVE-2025-24893

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.

    Published:Feb 20, 2025
    Last Modified:Feb 26, 2026
    EPS:Feb 20, 2025
    EPSS Score:0.94241
    CVSS Score:9.8

    CISA Notification

    Description

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.

    Required Action:

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Nov 20, 2025
    295 days ago
    Alert Date
    Oct 30, 2025
    316 days ago

    Affected Products

    Vendor
    Xwiki
    Product
    Xwiki

    Exploits

    https://jira.xwiki.org/browse/XWIKI-22149https://www.exploit-db.com/exploits/52429https://github.com/0xDTC/XWiki-Platform-RCE-CVE-2025-24893https://github.com/570RMBR3AK3R/xwiki-cve-2025-24893-pochttps://github.com/80Ottanta80/CVE-2025-24893-PoChttps://github.com/alaxar/CVE-2025-24893https://github.com/AliElKhatteb/CVE-2024-32019-POChttps://github.com/andwati/CVE-2025-24893https://github.com/Artemir7/CVE-2025-24893-EXPhttps://github.com/Ashwesker/Blackash-CVE-2025-24893https://github.com/AzureADTrent/CVE-2025-24893-Reverse-Shellhttps://github.com/b0ySie7e/CVE-2025-24893https://github.com/B1ack4sh/Blackash-CVE-2025-24893https://github.com/Bishben/xwiki-15.10.8-reverse-shell-cve-2025-24893https://github.com/BreakingRohit/CVE-2025-24893-PoChttps://github.com/CMassa/CVE-2025-24893https://github.com/D3Ext/CVE-2025-24893https://github.com/dhiaZnaidi/CVE-2025-24893-PoChttps://github.com/dollarboysushil/CVE-2025-24893-XWiki-Unauthenticated-RCE-Exploit-POChttps://github.com/endusdksla/xwiki-cve-2025-24893https://github.com/Fomovet/cve-2025-24893https://github.com/gmh5225/CVE-2025-24893-RCE-PoChttps://github.com/gotr00t0day/CVE-2025-24893https://github.com/gunzf0x/CVE-2025-24893https://github.com/hackersonsteroids/cve-2025-24893https://github.com/hasecto/CVE-2025-24893https://github.com/Hex00-0x4/CVE-2025-24893-XWiki-RCEhttps://github.com/ibadovulfat/CVE-2025-24893https://github.com/ibadovulfat/CVE-2025-24893_HackTheBox-Editor-Writeuphttps://github.com/ibrahmsql/CVE-2025-24893https://github.com/IIIeJlyXaKapToIIIKu/CVE-2025-24893-XWiki-unauthenticated-RCE-via-SolrSearchhttps://github.com/Infinit3i/CVE-2025-24893https://github.com/investigato/cve-2025-24893-pochttps://github.com/iSee857/CVE-2025-24893-PoChttps://github.com/Kai7788/CVE-2025-24893-RCE-PoChttps://github.com/kimtangker/CVE-2025-24893https://github.com/mah4nzfr/CVE-2025-24893https://github.com/MattiaCervelli/CVE-2025-24893_Analysishttps://github.com/nohack1212/CVE-2025-24893-https://github.com/nopgadget/CVE-2025-24893https://github.com/o0wo0o/CVE-2025-24893_Shellhttps://github.com/Retro023/CVE-2025-24893-POChttps://github.com/rippsec/CVE-2025-24893-XWiki-SSTI-RCEhttps://github.com/rvizx/CVE-2025-24893https://github.com/rvzsec/CVE-2025-24893https://github.com/Th3Gl0w/CVE-2025-24893-POChttps://github.com/The-Red-Serpent/CVE-2025-24893https://github.com/TomKingori/xwiki-cve-2025-24893-exploithttps://github.com/torjan0/xwiki_solrsearch-rce-exploithttps://github.com/vasilysaint/CVE-2025-24893https://github.com/WhiteDominion/CVE-2025-24893https://github.com/x0da6h/POC-for-CVE-2025-24893https://github.com/Y2F05p2w/CVE-2025-24893https://github.com/Yukik4z3/CVE-2025-24893https://github.com/zs1n/CVE-2025-24893https://www.exploit-db.com/exploits/52136

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High