vendor:
XWiki Platform
by:
Al Baradi Joy
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
RCE
CWE
Product Name: XWiki Platform
Affected Version From: Up to and including XWiki 15.10.10
Affected Version To: XWiki 15.10.10
Patch Exists: YES
Related CWE: CVE-2025-24893
CPE: a:xwiki:xwiki_platform
Platforms Tested:
2025
XWiki Platform – Remote Code Execution
XWiki Platform is vulnerable to a critical Remote Code Execution (RCE) vulnerability that allows guest users to execute arbitrary code remotely via the SolrSearch endpoint. This can result in a complete server compromise, granting the attacker the ability to run commands on the underlying system, impacting the confidentiality, integrity, and availability of the XWiki installation. The issue has been addressed in XWiki versions 15.10.11, 16.4.1, and 16.5.0RC1.
Mitigation:
Ensure to update XWiki to versions 15.10.11, 16.4.1, or 16.5.0RC1 to mitigate this vulnerability.