← Vulnerability feed

Vulnerability record · CVE-2025-66474 · published 10 December 2025

CVE-2025-66474: Xwiki-rendering code injection vulnerability

Xwiki · Xwiki Rendering

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, which attackers can exploit through RCE. Any user who can edit their own profile or any other document can execute arbitrary script macros, including Groovy and Python macros, which enable remote code execution as well as unrestricted read and write access to all wiki contents. This issue is fixed in versions 16.10.10, 17.4.3 and 17.6.0-rc-1.

8.7 CVSS 4.0 High EPSS 1.0% · top 38.0% CWE-95 · CWE-95CWE-94 · Code injection
8.7CVSS 4.0 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 6 tagged exploit
25 Sep 2026Last modified by NVD

Description

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, which attackers can exploit through RCE. Any user who can edit their own profile or any other document can execute arbitrary script macros, including Groovy and Python macros, which enable remote code execution as well as unrestricted read and write access to all wiki contents. This issue is fixed in versions 16.10.10, 17.4.3 and 17.6.0-rc-1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-66474 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2023-37908Xwiki-rendering cross-site scripting vulnerabilityXWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XH…EPSS 1.1%8.8CVE-2023-37912Xwiki-rendering vulnerabilityXWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwi…EPSS 1.2%6.5CVE-2026-24128Xwiki cross-site scripting vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-milestone-2 through 16.10.11, 1…EPSS 0.56%9.3CVE-2026-33017Langflow build_public_tmp endpoint unauthenticated remote code executionLangflow versions prior to 1.9.0 expose the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint without authentication, and when the optional data …KEVEPSS 25%analysed9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.8CVE-2024-36401GeoServer OGC request parameter XPath eval injection enables unauthenticated RCEGeoServer versions before 2.22.6, 2.23.6, 2.24.4, and 2.25.2 unsafely evaluate OGC request parameters as XPath expressions via the GeoTools commons-j…KEVEPSS 100%analysed7.8CVE-2023-7101Spreadsheet::ParseExcel Perl module code injection via Excel number format stringsSpreadsheet::ParseExcel 0.65, a Perl module for parsing Excel files, passes unvalidated input from a file into a string-type eval. Specifically, Numb…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2025-66474), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.