← Vulnerability feed

Vulnerability record · CVE-2025-55728 · published 9 September 2025

CVE-2025-55728: Xwiki pro macros code injection vulnerability

Xwiki · Pro Macros

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote code execution for any user who can edit any page The classes parameter is used without escaping in XWiki syntax, thus allowing XWiki syntax injection which enables remote code execution. Version 1.26.5 contains a patch for the issue.

9.8 CVSS 3.1 Critical EPSS 0.79% · top 45.4% CWE-95 · CWE-95CWE-94 · Code injection
9.8CVSS 3.1 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote code execution for any user who can edit any page The classes parameter is used without escaping in XWiki syntax, thus allowing XWiki syntax injection which enables remote code execution. Version 1.26.5 contains a patch for the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55728 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-55727Xwiki pro macros code injection vulnerabilityXWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to vers…EPSS 1.0%8.8CVE-2024-42489Xwiki pro macros injection vulnerabilityPro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` pag…EPSS 1.1%8.3CVE-2025-65036Xwiki pro macros missing authorization vulnerabilityXWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Veloc…EPSS 0.40%6.5CVE-2025-65089Xwiki pro macros missing authorization vulnerabilityXWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no v…EPSS 0.28%9.3CVE-2026-33017Langflow build_public_tmp endpoint unauthenticated remote code executionLangflow versions prior to 1.9.0 expose the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint without authentication, and when the optional data …KEVEPSS 25%analysed9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.8CVE-2024-36401GeoServer OGC request parameter XPath eval injection enables unauthenticated RCEGeoServer versions before 2.22.6, 2.23.6, 2.24.4, and 2.25.2 unsafely evaluate OGC request parameters as XPath expressions via the GeoTools commons-j…KEVEPSS 100%analysed7.8CVE-2023-7101Spreadsheet::ParseExcel Perl module code injection via Excel number format stringsSpreadsheet::ParseExcel 0.65, a Perl module for parsing Excel files, passes unvalidated input from a file into a string-type eval. Specifically, Numb…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2025-55728), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.