XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to SolrSearch. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to /xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20. If there is an output, and the title of the RSS feed contains Hello from search text:42, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit Main.SolrSearchMacros in SolrSearchMacros.xml on line 955 to match the rawResponse macro in macros.vm#L2824 with a content type of application/xml, instead of simply outputting the content of the feed.
CVE-2025-24893
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2025-10-30), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EPSS
- 100.0%
- KEV
- ⚠ Exploited
Published
February 20, 2025
Last Modified
October 31, 2025
Advisory Details (6)
Auto-updated May 30, 2026Known Exploited Vulnerabilities Catalog | CISA
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24893Remote code execution as guest via SolrSearchMacros request · Advisory · xwiki/xwiki-platform · GitHub
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rr6p-3pfg-562jcommit 67021db9b8ed (xwiki/xwiki-platform)
Patch available: xwiki/xwiki-platform xwiki-platform-17.4.7 (contains commit 67021db9b8ed)
https://github.com/xwiki/xwiki-platform/commit/67021db9b8ed26c2236a653269302a86bf01ef40xwiki-platform/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-templates/src/main/resources/templates/macros.vm at 67021db9b8ed26c2236a653269302a86bf01ef40 · xwiki/xwiki-platform · GitHub
https://github.com/xwiki/xwiki-platform/blob/67021db9b8ed26c2236a653269302a86bf01ef40/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-templates/src/main/resources/templates/macros.vm#L2824xwiki-platform/xwiki-platform-core/xwiki-platform-search/xwiki-platform-search-solr/xwiki-platform-search-solr-ui/src/main/resources/Main/SolrSearchMacros.xml at 568447cad5172d97d6bbcfda9f6183689c2cf086 · xwiki/xwiki-platform · GitHub
https://github.com/xwiki/xwiki-platform/blob/568447cad5172d97d6bbcfda9f6183689c2cf086/xwiki-platform-core/xwiki-platform-search/xwiki-platform-search-solr/xwiki-platform-search-solr-ui/src/main/resources/Main/SolrSearchMacros.xml#L955Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.xwiki.platform:xwiki-platform-search-solr-ui | — | 16.4.1 | — |
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 7× in last 7d / 21× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-19 14:40 UTCEG score recompute
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-17 10:37 UTCEG score recompute
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-07 19:01 UTCCISA KEV update
- 2026-07-07 17:16 UTCCISA KEV update
- 2026-07-06 16:26 UTCEPSS rescore
- 2026-07-01 19:16 UTCCISA KEV update
- 2026-06-29 19:12 UTCCISA KEV update
- 2026-06-25 19:15 UTCCISA KEV update
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 17:44 UTCCISA KEV update
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-18 16:13 UTCCISA KEV update
- 2026-06-16 19:33 UTCCISA KEV update
Show 24 moreShow fewer
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 19:33 UTCCISA KEV update
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-12 17:35 UTCCISA KEV update
- 2026-06-11 19:10 UTCCISA KEV update
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-09 18:42 UTCCISA KEV update
- 2026-06-09 17:12 UTCCISA KEV update
- 2026-06-08 19:16 UTCCISA KEV update
- 2026-06-08 17:26 UTCCISA KEV update
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-05 22:43 UTCCISA KEV update
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-03 19:09 UTCCISA KEV update
- 2026-06-02 18:32 UTCCISA KEV update
- 2026-06-01 20:42 UTCCISA KEV update
- 2026-05-29 22:25 UTCEG score recompute
- 2026-05-29 22:20 UTCCISA KEV update
- 2026-05-29 13:44 UTCEPSS rescore
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-52429First seen Sep 16, 2025
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
Open source ↗ - Open source ↗GitHub PoCb0ySie7e/CVE-2025-24893First seen Sep 3, 2025
- GitHub PoCD3Ext/CVE-2025-24893First seen Aug 9, 2025
POC exploit for CVE-2025-24893
Open source ↗ - GitHub PoCHex00-0x4/CVE-2025-24893-XWiki-RCEFirst seen Aug 8, 2025
This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch
Open source ↗ - GitHub PoC570RMBR3AK3R/xwiki-cve-2025-24893-pocFirst seen Aug 6, 2025
PoC for CVE-2025-24893
Open source ↗ - GitHub PoCgunzf0x/CVE-2025-24893First seen Aug 4, 2025
PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.
Open source ↗ - GitHub PoCdollarboysushil/CVE-2025-24893-XWiki-Unauthenticated-RCE-Exploit-POCFirst seen Aug 4, 2025
CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper handling of Groovy expressions in the SolrSearch macro.
Open source ↗ - GitHub PoCInfinit3i/CVE-2025-24893First seen Aug 3, 2025
PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronously. It allows arbitrary command execution through injection into RSS-based SolrSearch endpoints.
Open source ↗ - GitHub PoCAliElKhatteb/CVE-2024-32019-POCFirst seen Aug 3, 2025
this is a poc for the CVE-2025-24893
Open source ↗ - GitHub PoChackersonsteroids/cve-2025-24893First seen Aug 3, 2025
Modified exploit for CVE-2025-24893
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-94
Frequently asked(6)
What is CVE-2025-24893?
When was CVE-2025-24893 disclosed?
Is CVE-2025-24893 actively exploited?
What is the CVSS score of CVE-2025-24893?
Which products are affected by CVE-2025-24893?
How do I remediate CVE-2025-24893?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-24893
Is Your Infrastructure Affected by CVE-2025-24893?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.