XWiki Remote Macros vulnerable to remote code execution using the confluence details summary macro
Vulnerability Description
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-65036
Credits & Attribution
No credits recorded in the NVD database.
More from xwikisas
View All →Affected Vendor
xwikisas
View all reports →