XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricted attribute of the transformation context when executing nested macros. This allows executing macros that are normally forbidden in restricted mode, in particular script macros. The cache and chart macros that are bundled in XWiki use the vulnerable feature. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. To avoid the exploitation of this bug, comments can be disabled for untrusted users until an upgrade to a patched version has been performed. Note that users with edit rights will still be able to add comments via the object editor even if comments have been disabled.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21398 XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Github GHSA Github GHSA GHSA-32mf-57h2-64x9 XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 26 Aug 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki xwiki
CPEs cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:4.2:milestone1:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:4.2:milestone2:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:4.2:milestone3:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:4.2:rc1:*:*:*:*:*:*
Vendors & Products Xwiki xwiki

Tue, 15 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00885}


Mon, 14 Jul 2025 23:30:00 +0000

Type Values Removed Values Added
Description XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricted attribute of the transformation context when executing nested macros. This allows executing macros that are normally forbidden in restricted mode, in particular script macros. The cache and chart macros that are bundled in XWiki use the vulnerable feature. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. To avoid the exploitation of this bug, comments can be disabled for untrusted users until an upgrade to a patched version has been performed. Note that users with edit rights will still be able to add comments via the object editor even if comments have been disabled.
Title XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Weaknesses CWE-863
CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-07-15T19:49:20.208Z

Reserved: 2025-07-09T14:14:52.532Z

Link: CVE-2025-53836

cve-icon Vulnrichment

Updated: 2025-07-15T13:24:57.244Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-15T00:15:22.370

Modified: 2025-08-26T17:52:16.700

Link: CVE-2025-53836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-16T21:35:33Z