CVE-2025-49586: XWiki
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.
Affected products
- XWiki XWiki: from 7.3, before 16.4.7 (fixed in 16.4.7); from 16.5.0, before 16.10.3 (fixed in 16.10.3); version 7.2 only; version 17.0.0 only
Published 2025-06-13. Last modified 2026-06-17.