CVE-2024-52300: XWiki PDF Viewer Macro
Critical severity, CVSS 9.0. EPSS: 0.4% chance of exploitation in the next 30 days.
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the malicious code. This is fixed in 2.5.6.
Affected products
- XWiki PDF Viewer Macro: before 2.5.6 (fixed in 2.5.6)
Published 2024-11-13. Last modified 2026-06-17.