CVE-2024-55877
XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been fixed in XWiki 15.10.11, 16.4.1 and 16.5.0. It is possible to manually apply the patch to the page `XWiki.XWikiSyntaxMacrosList` as a workaround.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.56%
- CWE
- CWE-96
- Published
- 2024-12-12
- Last modified
- 2026-03-13
Affected products
- xwiki xwiki-platform
- xwiki xwiki-platform
- xwiki xwiki-platform
Weakness type
Related vulnerabilities
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2020-6144 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh
- CVE-2020-6143 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable wh
- CVE-2024-55662 — XWiki allows remote code execution through the extension sheet
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allo
- CVE-2022-43938 — Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
- CVE-2024-43400 — XWiki Platform allows XSS through XClass name in string properties