vendor:
                    XWiki Platform
                by:
                    Al Baradi Joy
                8.1
                        CVSS
                    CRITICAL
                    Remote Code Execution (RCE)
                    RCE
                        CWE
                    Product Name: XWiki Platform
                    Affected Version From:  Up to and including XWiki 15.10.10
                    Affected Version To:  XWiki 15.10.10
                    Patch Exists: YES
                    Related CWE: CVE-2025-24893
                    CPE:  a:xwiki:xwiki_platform
                    Platforms Tested:  
                    2025
                    XWiki Platform – Remote Code Execution
XWiki Platform is vulnerable to a critical Remote Code Execution (RCE) vulnerability that allows guest users to execute arbitrary code remotely via the SolrSearch endpoint. This can result in a complete server compromise, granting the attacker the ability to run commands on the underlying system, impacting the confidentiality, integrity, and availability of the XWiki installation. The issue has been addressed in XWiki versions 15.10.11, 16.4.1, and 16.5.0RC1.
Mitigation:
					Ensure to update XWiki to versions 15.10.11, 16.4.1, or 16.5.0RC1 to mitigate this vulnerability.