Vulnerability Description
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, which attackers can exploit through RCE. Any user who can edit their own profile or any other document can execute arbitrary script macros, including Groovy and Python macros, which enable remote code execution as well as unrestricted read and write access to all wiki contents. This issue is fixed in versions 16.10.10, 17.4.3 and 17.6.0-rc-1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Xwiki-Rendering | < 16.10.10 |
Related Weaknesses (CWE)
References
- https://github.com/xwiki/xwiki-platform/commit/12b780ccd5bca5fc8f74f46648d7e02faPatch
- https://github.com/xwiki/xwiki-rendering/commit/9b71a2ee035815cfc29cebbfe81dbdd9Patch
- https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-9xc6-c2rm-f27pPatchVendor Advisory
- https://jira.xwiki.org/browse/XRENDERING-693ExploitPatchVendor Advisory
- https://jira.xwiki.org/browse/XRENDERING-792ExploitPatchVendor Advisory
- https://jira.xwiki.org/browse/XRENDERING-793ExploitPatchVendor Advisory
- https://jira.xwiki.org/browse/XWIKI-23378PatchVendor Advisory
- https://jira.xwiki.org/browse/XRENDERING-693ExploitPatchVendor Advisory
- https://jira.xwiki.org/browse/XRENDERING-792ExploitPatchVendor Advisory
- https://jira.xwiki.org/browse/XRENDERING-793ExploitPatchVendor Advisory
FAQ
What is CVE-2025-66474?
CVE-2025-66474 is a vulnerability with a CVSS score of 8.8 (HIGH). XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 1...
How severe is CVE-2025-66474?
CVE-2025-66474 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66474?
Check the references section above for vendor advisories and patch information. Affected products include: Xwiki Xwiki-Rendering.