CVE-2025-24893
Last modified
CVE-2025-24893 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.90% chance of exploitation in the next 30 days.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Xwiki | >= 5.4, < 15.10.11 |
| Xwiki | Xwiki | >= 16.0.0, < 16.4.1 |
| Xwiki | Xwiki | 5.3 |
References
- https://jira.xwiki.org/browse/XWIKI-22149Exploit, Issue Tracking, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24893US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-24893?
How severe is CVE-2025-24893?
How do I fix CVE-2025-24893?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24888The SecureDrop Client is a desktop application for journalis…8.1
- CVE-2025-24889The SecureDrop Client is a desktop application for journalis…4.5
- CVE-2025-2489Insecure information storage vulnerability in NTFS Tools ver…6.8
- CVE-2025-24890gitoxide is an implementation of git written in Rust. Prior …6.8
- CVE-2025-24891Dumb Drop is a file upload application. Users with permissio…9.6
- CVE-2025-24892OpenProject is open-source, web-based project management sof…5.4
- CVE-2025-24894SPID.AspNetCore.Authentication is an AspNetCore Remote Authe…9.1
- CVE-2025-24895CIE.AspNetCore.Authentication is an AspNetCore Remote Authen…9.1
- CVE-2025-24896Misskey is an open source, federated social media platform. …8.1
- CVE-2025-24897Misskey is an open source, federated social media platform. …8.2
- CVE-2025-24898rust-openssl is a set of OpenSSL bindings for the Rust progr…6.3
- CVE-2025-24899reNgine is an automated reconnaissance framework for web app…7.5
Are you affected by CVE-2025-24893?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
