XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.
References
| Link | Resource |
|---|---|
| https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-472x-fwh9-r82f | Vendor Advisory |
Configurations
History
20 Feb 2026, 16:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-472x-fwh9-r82f - Vendor Advisory | |
| CPE | cpe:2.3:a:xwiki:pro_macros:*:*:*:*:*:*:*:* | |
| First Time |
Xwiki pro Macros
Xwiki |
05 Dec 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 17:16
Updated : 2026-02-20 16:51
NVD link : CVE-2025-65036
Mitre link : CVE-2025-65036
CVE.ORG link : CVE-2025-65036
JSON object : View
Products Affected
xwiki
- pro_macros
CWE
CWE-862
Missing Authorization
