Impact
A failure to properly escape rendering output lets a user inject script macros into HTML macros, which are then executed with full Groovy or Python privileges. The weakness is an Eval injection (CWE‑95) that permits arbitrary code execution, allowing an attacker to read or write any wiki content.
Affected Systems
XWiki Rendering v14.10.1 and earlier, and v15.0 RC1‑pre release users who can edit their own profile or any other document. These versions are vulnerable because they allow an unescaped macro to close an HTML macro and inject malicious content.
Risk and Exploitability
The CVSS score is 9.9, indicating critical severity, and EPSS is < 1%, suggesting a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the ability to edit or create content, which is commonly granted to regular users, so the attack vector is broadly available to anyone with edit rights. Successful exploitation results in full remote code execution and data compromise.
OpenCVE Enrichment
Github GHSA