Skip to main content
CRITICAL

CVE-2025-53836

XWiki Rendering is vulnerable to RCE attacks when processing nested macros

CVSS v3

9.9

CRITICAL

EPSS Score

2.5 %

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricted attribute of the transformation context when executing nested macros. This allows executing macros that are normally forbidden in restricted mode, in particular script macros. The cache and chart m

Technical details

CVSS v3 Vector
3.1
Published
2025-07-15
Last Modified
2025-08-26

Frequently asked questions

What is CVE-2025-53836?

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricted attribute of the transformation context when executing nested macros. This allows executing macros that are normally forbidden in restricted mode, in particular script macros. The cache and chart m

Is CVE-2025-53836 actively exploited?

A proof-of-concept exploit exists for CVE-2025-53836, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2025-53836?

CVE-2025-53836 has a CVSS v3 base score of 9.9 (CRITICAL severity), with vector string 3.1.

Is CVE-2025-53836 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key