CVE-2025-66474
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, which attackers can exploit through RCE. Any user who can edit their own profile or any other document can execute arbitrary script macros, including Groovy and Python macros, which enable remote code execution as well as unrestricted read and write access to all wiki contents. This issue is fixed in versions 16.10.10, 17.4.3 and 17.6.0-rc-1.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 1.02%
- CWE
- CWE-95
- Published
- 2025-12-10
- Last modified
- 2026-03-13
Affected products
- xwiki xwiki-rendering
- xwiki xwiki-rendering
- xwiki xwiki-rendering
Weakness type
Related vulnerabilities
- CVE-2026-80351 — Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
- CVE-2026-78550 — Improper Input Handling in Okta Access Gateway Management Console Exception Handler
- CVE-2026-48273 — ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
- CVE-2026-76190 — ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
- CVE-2026-79678 — Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service
- CVE-2026-85165 — n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement
- CVE-2026-65643 — Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute...
- CVE-2026-19295 — Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement