{"schema_version":1,"title":"Xwiki vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in Xwiki: 0 in the last 7 days and 5 in the last 90 days, 6 of them critical and 1 exploited in the wild. The most recent, CVE-2025-53837, was published on 18 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/xwiki","json_url":"https://junglewise.ai/threats/vendors/xwiki.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/xwiki","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":12,"critical":6,"exploited":1,"last_7_days":0,"last_30_days":3,"last_90_days":5,"last_365_days":11},"latest":[{"cve":"CVE-2025-53837","cvss":9.9,"epss":0.0064,"slug":"cve-2025-53837-xwiki-xwiki-rendering-xml-eval-injection-via-html-macro-escaping","title":"XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XH","severity":"critical","exploited":false,"published_at":"2026-09-18T16:17:03.527+00:00","url":"https://junglewise.ai/threats/cve-2025-53837-xwiki-xwiki-rendering-xml-eval-injection-via-html-macro-escaping"},{"cve":"CVE-2026-53966","cvss":4,"epss":0.0077,"slug":"cve-2026-53966-xwiki-platform-live-data-privilege-escalation-through-edit-api","title":"XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API all","severity":"high","exploited":false,"published_at":"2026-09-15T15:17:17.533+00:00","url":"https://junglewise.ai/threats/cve-2026-53966-xwiki-platform-live-data-privilege-escalation-through-edit-api"},{"cve":"CVE-2026-34151","cvss":4,"epss":0.0106,"slug":"cve-2026-34151-xwiki-platform-path-traversal-in-skin-action-endpoint","title":"XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double","severity":"high","exploited":false,"published_at":"2026-09-14T18:17:47.107+00:00","url":"https://junglewise.ai/threats/cve-2026-34151-xwiki-platform-path-traversal-in-skin-action-endpoint"},{"cve":"CVE-2026-48048","cvss":7.5,"epss":0.0065,"slug":"cve-2026-48048-xwiki-platform-password-hash-disclosure-in-livetable-results","title":"XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6","severity":"high","exploited":false,"published_at":"2026-08-10T16:19:47.967+00:00","url":"https://junglewise.ai/threats/cve-2026-48048-xwiki-platform-password-hash-disclosure-in-livetable-results"},{"cve":"CVE-2023-37465","cvss":6.5,"slug":"cve-2023-37465-xwiki-discussion-extension-csrf-in-message-deletion-endpoint","title":"XWiki Discussion Extension CSRF in message deletion endpoint","severity":"medium","exploited":false,"published_at":"2026-07-27T17:04:00+00:00","url":"https://junglewise.ai/threats/cve-2023-37465-xwiki-discussion-extension-csrf-in-message-deletion-endpoint"},{"cve":"CVE-2026-48047","cvss":4,"epss":0.0065,"slug":"cve-2026-48047-xwiki-platform-path-traversal-in-webjar-api","title":"XWiki Platform path traversal in WebJar API","severity":"medium","exploited":false,"published_at":"2026-05-26T19:33:44+00:00","url":"https://junglewise.ai/threats/cve-2026-48047-xwiki-platform-path-traversal-in-webjar-api"},{"cve":"CVE-2026-33137","cvss":4,"epss":0.0088,"slug":"cve-2026-33137-xwiki-platform-missing-authorization-in-rest-api-xar-import","title":"XWiki Platform missing authorization in REST API XAR import","severity":"critical","exploited":false,"published_at":"2026-05-20T20:16:37.567+00:00","url":"https://junglewise.ai/threats/cve-2026-33137-xwiki-platform-missing-authorization-in-rest-api-xar-import"},{"cve":"CVE-2026-23734","cvss":4,"epss":0.1956,"slug":"cve-2026-23734-xwiki-platform-path-traversal-in-ssx-and-jsx-endpoints","title":"XWiki Platform path traversal in ssx and jsx endpoints","severity":"critical","exploited":false,"published_at":"2026-05-20T20:16:36.027+00:00","url":"https://junglewise.ai/threats/cve-2026-23734-xwiki-platform-path-traversal-in-ssx-and-jsx-endpoints"},{"cve":"CVE-2026-33229","cvss":9.8,"epss":0.0121,"slug":"cve-2026-33229-xwiki-platform-sandbox-bypass-in-velocity-scripting-api","title":"XWiki Platform sandbox bypass in Velocity scripting API","severity":"critical","exploited":false,"published_at":"2026-04-08T16:16:23.43+00:00","url":"https://junglewise.ai/threats/cve-2026-33229-xwiki-platform-sandbox-bypass-in-velocity-scripting-api"},{"cve":"CVE-2025-66024","cvss":9,"epss":0.0037,"slug":"cve-2025-66024-xwiki-blog-application-stored-xss-in-post-title","title":"The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15","severity":"critical","exploited":false,"published_at":"2026-03-04T22:16:11.677+00:00","url":"https://junglewise.ai/threats/cve-2025-66024-xwiki-blog-application-stored-xss-in-post-title"},{"cve":"CVE-2025-24893","cvss":9.8,"epss":0.9366,"slug":"cve-2025-24893-xwiki-platform-eval-injection-in-solrsearch","title":"XWiki Platform eval injection in SolrSearch","severity":"critical","exploited":true,"published_at":"2025-10-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-24893-xwiki-platform-eval-injection-in-solrsearch"},{"cve":"CVE-2025-49580","cvss":4,"epss":0.0046,"slug":"cve-2025-49580-xwiki-privilege-escalation-via-link-refactoring","title":"XWiki privilege escalation via link refactoring","severity":"high","exploited":false,"published_at":"2025-06-13T20:24:24+00:00","url":"https://junglewise.ai/threats/cve-2025-49580-xwiki-privilege-escalation-via-link-refactoring"}],"vendor":{"hub":true,"name":"Xwiki","slug":"xwiki","homepage":"https://www.xwiki.org/","description":"An open-source software development organization that maintains the XWiki enterprise wiki platform.","url":"https://junglewise.ai/threats/vendors/xwiki"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-24893","cvss":9.8,"epss":0.9366,"slug":"cve-2025-24893-xwiki-platform-eval-injection-in-solrsearch","title":"XWiki Platform eval injection in SolrSearch","severity":"critical","exploited":true,"published_at":"2025-10-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-24893-xwiki-platform-eval-injection-in-solrsearch"},{"cve":"CVE-2025-53837","cvss":9.9,"epss":0.0064,"slug":"cve-2025-53837-xwiki-xwiki-rendering-xml-eval-injection-via-html-macro-escaping","title":"XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XH","severity":"critical","exploited":false,"published_at":"2026-09-18T16:17:03.527+00:00","url":"https://junglewise.ai/threats/cve-2025-53837-xwiki-xwiki-rendering-xml-eval-injection-via-html-macro-escaping"},{"cve":"CVE-2026-33229","cvss":9.8,"epss":0.0121,"slug":"cve-2026-33229-xwiki-platform-sandbox-bypass-in-velocity-scripting-api","title":"XWiki Platform sandbox bypass in Velocity scripting API","severity":"critical","exploited":false,"published_at":"2026-04-08T16:16:23.43+00:00","url":"https://junglewise.ai/threats/cve-2026-33229-xwiki-platform-sandbox-bypass-in-velocity-scripting-api"},{"cve":"CVE-2025-66024","cvss":9,"epss":0.0037,"slug":"cve-2025-66024-xwiki-blog-application-stored-xss-in-post-title","title":"The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15","severity":"critical","exploited":false,"published_at":"2026-03-04T22:16:11.677+00:00","url":"https://junglewise.ai/threats/cve-2025-66024-xwiki-blog-application-stored-xss-in-post-title"},{"cve":"CVE-2026-23734","cvss":4,"epss":0.1956,"slug":"cve-2026-23734-xwiki-platform-path-traversal-in-ssx-and-jsx-endpoints","title":"XWiki Platform path traversal in ssx and jsx endpoints","severity":"critical","exploited":false,"published_at":"2026-05-20T20:16:36.027+00:00","url":"https://junglewise.ai/threats/cve-2026-23734-xwiki-platform-path-traversal-in-ssx-and-jsx-endpoints"},{"cve":"CVE-2026-33137","cvss":4,"epss":0.0088,"slug":"cve-2026-33137-xwiki-platform-missing-authorization-in-rest-api-xar-import","title":"XWiki Platform missing authorization in REST API XAR import","severity":"critical","exploited":false,"published_at":"2026-05-20T20:16:37.567+00:00","url":"https://junglewise.ai/threats/cve-2026-33137-xwiki-platform-missing-authorization-in-rest-api-xar-import"},{"cve":"CVE-2026-48048","cvss":7.5,"epss":0.0065,"slug":"cve-2026-48048-xwiki-platform-password-hash-disclosure-in-livetable-results","title":"XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6","severity":"high","exploited":false,"published_at":"2026-08-10T16:19:47.967+00:00","url":"https://junglewise.ai/threats/cve-2026-48048-xwiki-platform-password-hash-disclosure-in-livetable-results"},{"cve":"CVE-2026-34151","cvss":4,"epss":0.0106,"slug":"cve-2026-34151-xwiki-platform-path-traversal-in-skin-action-endpoint","title":"XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double","severity":"high","exploited":false,"published_at":"2026-09-14T18:17:47.107+00:00","url":"https://junglewise.ai/threats/cve-2026-34151-xwiki-platform-path-traversal-in-skin-action-endpoint"},{"cve":"CVE-2026-53966","cvss":4,"epss":0.0077,"slug":"cve-2026-53966-xwiki-platform-live-data-privilege-escalation-through-edit-api","title":"XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API all","severity":"high","exploited":false,"published_at":"2026-09-15T15:17:17.533+00:00","url":"https://junglewise.ai/threats/cve-2026-53966-xwiki-platform-live-data-privilege-escalation-through-edit-api"},{"cve":"CVE-2025-49580","cvss":4,"epss":0.0046,"slug":"cve-2025-49580-xwiki-privilege-escalation-via-link-refactoring","title":"XWiki privilege escalation via link refactoring","severity":"high","exploited":false,"published_at":"2025-06-13T20:24:24+00:00","url":"https://junglewise.ai/threats/cve-2025-49580-xwiki-privilege-escalation-via-link-refactoring"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"XWiki Platform","slug":"platform","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/platform"}]}