Back to Database
Status published
High
CVE-2025-27604
XWiki Confluence Migrator Pro's homepage is public
Vulnerability Description
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27604
Credits & Attribution
No credits recorded in the NVD database.
References
More from xwikisas
View All →CVE-2025-65089
XWiki view file macro: User can view content of office file without view rights on the attachment
Medium
6.8
CVE-2025-65036
XWiki Remote Macros vulnerable to remote code execution using the confluence details summary macro
High
8.3
CVE-2025-55730
XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
Critical
10
CVE-2025-55729
XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
Critical
10
CVE-2025-55728
XWiki Remote Macros vulnerable to remote code execution using the panel macro
Critical
10
Affected Vendor
xwikisas
View all reports →Affected Software
application-confluence-migrator-pro
Vulnerable Versions:
< 1.11.7
Timeline
Official Publish:
March 7th, 2025
Last Modified:
March 7th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N