9.8
CRITICAL CVSS 3.1
CVE-2025-24893
XWiki Platform SolrSearch Remote Code Execution
Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.

INFO

Published Date :

Feb. 20, 2025, 8:15 p.m.

Last Modified :

May 7, 2025, 6:08 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2025-24893 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Xwiki xwiki
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL [email protected]
CVSS 3.1 CRITICAL [email protected]
Solution
Upgrade XWiki Platform to a patched version for RCE vulnerability.
  • Upgrade XWiki to versions 15.10.11, 16.4.1, or 16.5.0RC1.
  • Alternatively, edit SolrSearchMacros.xml on line 955.
Public PoC/Exploit Available at Github

CVE-2025-24893 has a 33 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-24893 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell. Built during process of pwning HTB “Editor”

Python

Updated: 2 days, 2 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 26, 2025, 8:12 p.m. This repo has been linked 1 different CVEs too.

A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.

Python

Updated: 2 days, 11 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 26, 2025, 10:33 a.m. This repo has been linked 1 different CVEs too.

Some poorly crafted exploit scripts

Python

Updated: 6 days, 8 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 22, 2025, 6:56 a.m. This repo has been linked 1 different CVEs too.

PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)

cve-2025-24893 poc rce-exploit xwiki

Python

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : Aug. 13, 2025, 9:49 p.m. This repo has been linked 1 different CVEs too.

A POC for CVE-2025-24893 written in python

Python

Updated: 2 weeks, 4 days ago
0 stars 0 fork 0 watcher
Born at : Aug. 9, 2025, 11:38 p.m. This repo has been linked 1 different CVEs too.

None

Updated: 2 weeks, 5 days ago
0 stars 0 fork 0 watcher
Born at : Aug. 9, 2025, 9:33 p.m. This repo has been linked 1 different CVEs too.

POC exploit for CVE-2025-24893

cve-2025-24893 python

Python

Updated: 2 weeks, 3 days ago
1 stars 0 fork 0 watcher
Born at : Aug. 9, 2025, 3:51 p.m. This repo has been linked 2 different CVEs too.

XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC

Python

Updated: 2 weeks, 6 days ago
0 stars 0 fork 0 watcher
Born at : Aug. 8, 2025, 8:01 p.m. This repo has been linked 1 different CVEs too.

POC

Python

Updated: 2 weeks, 6 days ago
0 stars 0 fork 0 watcher
Born at : Aug. 8, 2025, 9:48 a.m. This repo has been linked 1 different CVEs too.

This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch

Python

Updated: 2 weeks, 6 days ago
5 stars 0 fork 0 watcher
Born at : Aug. 8, 2025, 5:38 a.m. This repo has been linked 1 different CVEs too.

None

TypeScript Shell

Updated: 2 weeks, 5 days ago
1 stars 0 fork 0 watcher
Born at : Aug. 7, 2025, 10:34 p.m. This repo has been linked 1 different CVEs too.

Bash POC script for RCE vulnerability in XWiki Platform

Shell

Updated: 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Aug. 7, 2025, 9:36 p.m. This repo has been linked 1 different CVEs too.

CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform.

Python

Updated: 2 weeks, 5 days ago
1 stars 0 fork 0 watcher
Born at : Aug. 7, 2025, 10:20 a.m. This repo has been linked 1 different CVEs too.

PoC for CVE-2025-24893

Python Shell

Updated: 3 weeks, 1 day ago
1 stars 1 fork 1 watcher
Born at : Aug. 6, 2025, 3:56 p.m. This repo has been linked 1 different CVEs too.

Proof-of-Concept exploit for CVE-2025-24893, an unauthenticated Remote Code Execution (RCE) vulnerability in XWiki. Exploits a template injection flaw in the SolrSearch endpoint via Groovy script execution.

Rust

Updated: 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Aug. 5, 2025, 4:29 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-24893 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2025-24893 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    May. 07, 2025

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-94
    Added CPE Configuration OR *cpe:2.3:a:xwiki:xwiki:5.3:milestone2:*:*:*:*:*:* *cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* versions from (including) 16.0.0 up to (excluding) 16.4.1 *cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* versions from (including) 5.4 up to (excluding) 15.10.11 *cpe:2.3:a:xwiki:xwiki:5.3:-:*:*:*:*:*:* *cpe:2.3:a:xwiki:xwiki:5.3:rc1:*:*:*:*:*:*
    Added Reference Type GitHub, Inc.: https://github.com/xwiki/xwiki-platform/blob/568447cad5172d97d6bbcfda9f6183689c2cf086/xwiki-platform-core/xwiki-platform-search/xwiki-platform-search-solr/xwiki-platform-search-solr-ui/src/main/resources/Main/SolrSearchMacros.xml#L955 Types: Product
    Added Reference Type GitHub, Inc.: https://github.com/xwiki/xwiki-platform/blob/67021db9b8ed26c2236a653269302a86bf01ef40/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-templates/src/main/resources/templates/macros.vm#L2824 Types: Product
    Added Reference Type GitHub, Inc.: https://github.com/xwiki/xwiki-platform/commit/67021db9b8ed26c2236a653269302a86bf01ef40 Types: Patch
    Added Reference Type GitHub, Inc.: https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rr6p-3pfg-562j Types: Vendor Advisory
    Added Reference Type GitHub, Inc.: https://jira.xwiki.org/browse/XWIKI-22149 Types: Exploit, Issue Tracking, Vendor Advisory
  • New CVE Received by [email protected]

    Feb. 20, 2025

    Action Type Old Value New Value
    Added Description XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-95
    Added Reference https://github.com/xwiki/xwiki-platform/blob/568447cad5172d97d6bbcfda9f6183689c2cf086/xwiki-platform-core/xwiki-platform-search/xwiki-platform-search-solr/xwiki-platform-search-solr-ui/src/main/resources/Main/SolrSearchMacros.xml#L955
    Added Reference https://github.com/xwiki/xwiki-platform/blob/67021db9b8ed26c2236a653269302a86bf01ef40/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-templates/src/main/resources/templates/macros.vm#L2824
    Added Reference https://github.com/xwiki/xwiki-platform/commit/67021db9b8ed26c2236a653269302a86bf01ef40
    Added Reference https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rr6p-3pfg-562j
    Added Reference https://jira.xwiki.org/browse/XWIKI-22149
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 9.8
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact