XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.
References
Configurations
No configuration.
History
05 Dec 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 17:16
Updated : 2025-12-08 18:26
NVD link : CVE-2025-65036
Mitre link : CVE-2025-65036
CVE.ORG link : CVE-2025-65036
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
