CVE Explorer
CVE-2025-66474
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, which attackers can exploit through RCE. Any user who can edit their own profile or any other document can execute arbitrary script macros, including Groovy and Python macros, which enable remote code exec
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"xwiki-rendering","vendor":"xwiki","versions":[{"status":"affected","version":"< 16.10.10"},{"status":"affected","version":">= 17.0.0-rc-1, < 17.4.3"},{"status":"affected","version":">= 17.5.0-rc-1, < 17.6.0-rc-1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-95","description":"CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/problemTypes/0/descriptions/0
Source references
10 source assertions{"name":"https://github.com/xwiki/xwiki-platform/commit/12b780ccd5bca5fc8f74f46648d7e02fa04fbc11","tags":["x_refsource_MISC"],"url":"https://github.com/xwiki/xwiki-platform/commit/12b780ccd5bca5fc8f74f46648d7e02fa04fbc11"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/references/1
{"name":"https://github.com/xwiki/xwiki-rendering/commit/9b71a2ee035815cfc29cebbfe81dbdd98f941d49","tags":["x_refsource_MISC"],"url":"https://github.com/xwiki/xwiki-rendering/commit/9b71a2ee035815cfc29cebbfe81dbdd98f941d49"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/references/2
{"name":"https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-9xc6-c2rm-f27p","tags":["x_refsource_CONFIRM"],"url":"https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-9xc6-c2rm-f27p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/references/0
{"name":"https://jira.xwiki.org/browse/XRENDERING-693","tags":["x_refsource_MISC"],"url":"https://jira.xwiki.org/browse/XRENDERING-693"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/references/3
{"tags":["exploit"],"url":"https://jira.xwiki.org/browse/XRENDERING-693"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/adp/0/references/2
{"name":"https://jira.xwiki.org/browse/XRENDERING-792","tags":["x_refsource_MISC"],"url":"https://jira.xwiki.org/browse/XRENDERING-792"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/references/4
{"tags":["exploit"],"url":"https://jira.xwiki.org/browse/XRENDERING-792"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/adp/0/references/1
{"tags":["exploit"],"url":"https://jira.xwiki.org/browse/XRENDERING-793"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/adp/0/references/0
{"name":"https://jira.xwiki.org/browse/XRENDERING-793","tags":["x_refsource_MISC"],"url":"https://jira.xwiki.org/browse/XRENDERING-793"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/references/5
{"name":"https://jira.xwiki.org/browse/XWIKI-23378","tags":["x_refsource_MISC"],"url":"https://jira.xwiki.org/browse/XWIKI-23378"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a8477f0e4d024894d378a6eb064951d799841976fcce59a59b6497e131c193eb · sha256:e1dc5d1a0d6ba21e… · /containers/cna/references/6
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.