CVE-2025-24893
About
Rainforest analyst review
XWiki Platform evaluates content passed to its SolrSearch endpoint through the wiki's macro system. Because the search text is rendered without restriction, an unauthenticated guest can supply a payload combining the async and groovy macros so that arbitrary Groovy code is executed server-side. A single crafted GET request to /xwiki/bin/get/Main/SolrSearch is enough to run code, compromising the confidentiality, integrity, and availability of the entire XWiki installation.
XWiki is used as an internal knowledge base and collaboration platform, frequently holding documentation, internal processes, and embedded secrets, and instances are often reachable to a broad user population or the internet. The trigger is trivial and reliable, so public proof-of-concept code circulated and the flaw was actively exploited, including for cryptomining and follow-on access, earning a place on CISA's KEV list. Upgrade to XWiki 15.10.11, 16.4.1, or 16.5.0RC1; where an immediate upgrade is not possible, apply the documented SolrSearchMacros workaround, and because exploitation is simple and was widespread, check exposed instances for injected code execution and unexpected outbound activity.
References
- https://github.com/xwiki/xwiki-platform/blob/568447cad5172d97d6bbcfda9f6183689c2cf086/xwiki-platform-core/xwiki-platform-search/xwiki-platform-search-solr/xwiki-platform-search-solr-ui/src/main/resources/Main/SolrSearchMacros.xml#L955
- https://github.com/xwiki/xwiki-platform/blob/67021db9b8ed26c2236a653269302a86bf01ef40/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-templates/src/main/resources/templates/macros.vm#L2824
- https://github.com/xwiki/xwiki-platform/commit/67021db9b8ed26c2236a653269302a86bf01ef40
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rr6p-3pfg-562j
- https://jira.xwiki.org/browse/XWIKI-22149
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24893
Related CVEs
Frequently asked questions
What is CVE-2025-24893?
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation.
How severe is CVE-2025-24893?
CVE-2025-24893 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2025-24893 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2025-24893?
Public advisories list the following as affected: xwiki. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2025-24893?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
