CVE-2025-27603: Xwikisas Application-Confluence-Migrator-Pro
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0.
Affected products
- Xwikisas Application-Confluence-Migrator-Pro: after 1.0, before 1.2.0 (fixed in 1.2.0)
Published 2025-03-07. Last modified 2026-06-17.