An RCE vulnerability in XWiki was found allowing unauthenticated attackers to execute arbitrary Groovy code remotely without authentication or prior access.
-
Updated
Nov 28, 2025 - Python
An RCE vulnerability in XWiki was found allowing unauthenticated attackers to execute arbitrary Groovy code remotely without authentication or prior access.
This vulnerability affects XWiki Platform versions >= 5.3-milestone-2 and = 16.0.0-rc-1 and Successful exploitation may result in the remote code execution under the privileges of the web server, potentially exposing sensitive data or disrupting survey operations.
🛠️ Exploit a critical remote code execution vulnerability in XWiki, affecting its confidentiality and integrity; patches available in recent versions.
Add a description, image, and links to the xwiki-exploit topic page so that developers can more easily learn about it.
To associate your repository with the xwiki-exploit topic, visit your repo's landing page and select "manage topics."