CVE-2025-53836
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
CVSS v3
9.9
CRITICAL
EPSS Score
2.5 %
exploit probability
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
Description
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricted attribute of the transformation context when executing nested macros. This allows executing macros that are normally forbidden in restricted mode, in particular script macros. The cache and chart m
Technical details
- CVSS v3 Vector
- 3.1
- Published
- 2025-07-15
- Last Modified
- 2025-08-26
Frequently asked questions
What is CVE-2025-53836?
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricted attribute of the transformation context when executing nested macros. This allows executing macros that are normally forbidden in restricted mode, in particular script macros. The cache and chart m
Is CVE-2025-53836 actively exploited?
A proof-of-concept exploit exists for CVE-2025-53836, but active exploitation has not been confirmed at this time.
What is the CVSS score for CVE-2025-53836?
CVE-2025-53836 has a CVSS v3 base score of 9.9 (CRITICAL severity), with vector string 3.1.
Is CVE-2025-53836 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2025 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).