cbcvebase.

Xwikisas Xwiki-Pro-Macros vulnerabilities

7 known vulnerabilities affecting xwikisas/xwiki-pro-macros.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-55730P2CRITICALCVSS 10.0v>= 1.0, < 1.26.52025-09-09
CVE-2025-55730 [CRITICAL] CWE-116 CVE-2025-55730: XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Conf XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote code execution for any user who can edit any page. The classes parameter is used without escaping in XWiki sy
nvd
CVE-2025-55729P2CRITICALCVSS 10.0v>= 1.0, < 1.26.52025-09-09
CVE-2025-55729 [CRITICAL] CWE-116 CVE-2025-55729: XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Conf XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the ac:type in the ConfluenceLayoutSection macro allows remote code execution for any user who can edit any page The classes parameter is used without escaping in XWiki
nvd
CVE-2025-55727P2CRITICALCVSS 9.8v>= 1.0, < 1.26.52025-09-09
CVE-2025-55727 [CRITICAL] CWE-95 CVE-2025-55727: XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Conf XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code execution for any user who can edit any page or who can access the CKEditor converter. The width parameter is
nvd
CVE-2025-55728P2CRITICALCVSS 9.8v>= 1.0, < 1.26.52025-09-09
CVE-2025-55728 [CRITICAL] CWE-95 CVE-2025-55728: XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Conf XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote code execution for any user who can edit any page The classes parameter is used without escaping in XWiki syntax,
nvd
CVE-2024-42489P3HIGHCVSS 8.8v>= 1.0, < 1.10.12024-08-12
CVE-2024-42489 [HIGH] CWE-74 CVE-2024-42489: Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user wi Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed in 1.10.1.
nvd
CVE-2025-65036P3HIGHCVSS 8.3fixed in 1.27.12025-12-05
CVE-2025-65036 [HIGH] CWE-862 CVE-2025-65036: XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Conf XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.
nvd
CVE-2025-65089P3MEDIUMCVSS 6.5fixed in 1.27.02025-11-19
CVE-2025-65089 [MEDIUM] CWE-862 CVE-2025-65089: XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Conf XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.
nvd
Xwikisas Xwiki-Pro-Macros vulnerabilities | cvebase