Vulnerability Description
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Pro Macros | < 1.27.0 |
Related Weaknesses (CWE)
References
- https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-8c52-x9w7-Vendor Advisory
- https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-8c52-x9w7-Vendor Advisory
FAQ
What is CVE-2025-65089?
CVE-2025-65089 is a vulnerability with a CVSS score of 6.8 (MEDIUM). XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an offi...
How severe is CVE-2025-65089?
CVE-2025-65089 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65089?
Check the references section above for vendor advisories and patch information. Affected products include: Xwiki Pro Macros.