{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/xwiki-rendering-xml--14.10.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:xwiki:xwiki_rendering:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2025-53837"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["xwiki-rendering-xml (\u003c 14.10.2)"],"_cs_severities":["critical"],"_cs_tags":["injection","rce","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["XWiki"],"content_html":"\u003cp\u003eThe xwiki-rendering-xml component is vulnerable to an evaluation injection issue (CVE-2025-53837) due to insufficient escaping of rendering output when used within HTML macros. An attacker with standard document editing permissions, such as the ability to edit their own user profile or other wiki documents, can craft malicious input that prematurely closes the HTML macro block. This enables the injection of arbitrary script macros, including Groovy and Python. Because these macros are executed with programming rights, the impact includes full, unrestricted read and write access to all wiki content and potential remote code execution on the underlying server. The vulnerability affects XWiki versions prior to 14.10.2 and 15.0 RC1. Defenders should prioritize patching to the identified versions to prevent unauthorized script execution via the rendering pipeline.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker full control over the wiki installation, including data exfiltration and administrative control via script execution. The vulnerability is highly impactful due to the broad nature of programming rights in XWiki, which effectively elevates standard user document-editing access to full system command execution capabilities within the application context.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade XWiki installations utilizing xwiki-rendering-xml to version 14.10.2 or 15.0 RC1 immediately to remediate CVE-2025-53837.\u003c/li\u003e\n\u003cli\u003eReview and audit user-created documents and profile pages for suspicious object additions, specifically looking for those utilizing the 'XWiki.UIExtensionClass'.\u003c/li\u003e\n\u003cli\u003eRestrict document editing permissions to trusted users to reduce the potential attack surface while the upgrade is pending.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:48:26Z","date_published":"2026-09-18T19:48:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-xwiki-rendering-eval-injection/","summary":"An evaluation injection vulnerability in xwiki-rendering-xml allows authenticated users to achieve remote code execution by injecting script macros into HTML macro output.","title":"Eval Injection in XWiki Rendering XML","url":"https://feed.craftedsignal.io/briefs/2026-09-xwiki-rendering-eval-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Xwiki-Rendering-Xml (\u003c 14.10.2)","version":"https://jsonfeed.org/version/1.1"}