CVE-2025-65036

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.
Configurations

No configuration.

History

05 Dec 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 17:16

Updated : 2025-12-08 18:26


NVD link : CVE-2025-65036

Mitre link : CVE-2025-65036

CVE.ORG link : CVE-2025-65036


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization