CVE-2025-24893:
XWiki RCE
CVE-2025-24893 is an unauthenticated remote code execution bug in XWiki: a guest can send a crafted request to the SolrSearch feature that gets evaluated on the server, letting the attacker run arbitrary code. That can lead to full compromise of the XWiki instance (and potentially the host), including data theft, tampering, or taking the service down.
Below are general examples of techniques, methods, and proof-of-concept approaches used to demonstrate this vulnerability in a controlled environment.
Start a reverse shell
Run the exploit
9.8
Critical risk
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Compexity
low
Privileges
none
Affected
>= 5.3-milestone-2, < 15.10.11, >= 16.0.0-rc-1, < 16.4.1
Patched
15.10.11, 16.4.1