CVE-2025-24893General(xwiki / xwiki)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch xwiki xwiki systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-20. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-95CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xwiki

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • General: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-02-05); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
xwiki

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-02-05: 3Mentions · 2026-04-08: 1Mentions · 2026-04-24: 1Mentions · 2026-06-11: 1Mentions · 2026-08-20: 1Mentions · 2026-09-09: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-09-09: 1Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-09-09: 1Technical Details · 2026-02-05: 3Technical Details · 2026-04-24: 1Technical Details · 2026-06-11: 1Technical Details · 2026-09-09: 102-0504-0804-2406-1108-2009-09
Signal classification3 categories
General
337.5%
Active Exploitation
337.5%
Patch
225.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-053
General1Patch2
2026-04-081
Active Exploitation1
2026-04-241
General1
2026-06-111
Active Exploitation1
2026-08-201
General1
2026-09-091
Active Exploitation1
Full discourse8 posts
  • Crowdfense@crowdfense
    General

    The following vulnerabilities have been added to our feed: CVE-2025-53136: NT OS KASLR Bypass CVE-2025-30397: Internet Explorer/Edge Chakra Engine RCE CVE-2025-59287: Windows Server Update RCE CVE-2025-24893: XWiki Groovy Injection RCE https://www.crowdfense.com/n-day-feed/

    Post summary

    The post lists four new CVEs with short technical descriptors, providing no further detail on PoCs, exploits, patches, or active exploitation.

    05033212.5K
    2.9K followersView on X
  • Cloudflare Changelog@CFchangelog
    Patch

    🛡️ New WAF detections are LIVE! We're now blocking exploits for CVE-2025-64459 (Django SQLi) &amp; CVE-2025-24893 (XWiki RCE). Keeping your apps secure is our priority! 🚀 https://developers.cloudflare.com/changelog/2026-02-02-waf-release/

    Post summary

    Cloudflare’s new WAF release now actively blocks exploits for CVE‑2025‑64459 (Django SQLi) and CVE‑2025‑24893 (XWiki RCE), providing a mitigation for affected applications.

    0202021.1K
    1.1K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet lists the 25 most frequently attempted exploitation CVEs, indicating that these vulnerabilities are currently being targeted in the wild.

    070921.2K
    5.5K followersView on X
  • Bla_Ze 🔥🔥@KuveY81945
    General

    just rooted HTB Editor 🎯 full chain: XWiki SSTI RCE → credential reuse → ndsudo PATH hijacking for root. CVE-2025-24893 + CVE-2024-32019.https://labs.hackthebox.com/achievement/machine/3216229/684 #HackTheBox #HachTheBoxOndo #HTB #CyberSecurity #EthicalHacking #InfoSec #PenTesting

    Post summary

    The post describes a successful exploitation chain of two CVEs in a Hack The Box machine, outlining the attack flow but providing no PoC code, patches, or evidence of real‑world attacks.

    00030734
    16 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2023-46604 CVE-2026-61241 CVE-2025-6934 CVE-2025-24893 CVE-2026-60137 CVE-2026-63030 ..🧵👇

    Post summary

    A daily digest announces several newly disclosed CVEs without providing any detailed technical information, PoC references, or exploitation status.

    1001091
    37 followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Active Exploitation

    CVE-2025-24893、XWiki PlatformのRCE脆弱性が悪用。 クラウド攻撃のハードルがAIで急低下。 ↓詳細はリプライで #クラウドセキュリティ https://t.co/gClHvAVOOZ

    Post summary

    CVE-2025-24893, an RCE vulnerability in XWiki Platform, is reported as actively exploited, though no PoC or patch information is provided.

    1001055
    275 followersView on X
  • @pedri77@pedri77
    Active Exploitation

    RondoDox botnet exploits unpatched XWiki flaw CVE-2025-24893 to gain RCE and infect more servers, despite fixes released in February 2025. RondoDox is targeting unpatched XWiki servers via critical RCE flaw CVE-2025-248... https://f.mtr.cool/8ljwkiaa17

    Post summary

    RondoDox botnet is actively exploiting the unpatched XWiki vulnerability CVE‑2025‑24893 for remote code execution, even though a patch was released in February 2025.

    0000050
    2.1K followersView on X
  • Miguel Vera@mveracf
    Patch

    🛡️ New WAF detections are here! Protecting against critical vulnerabilities like CVE-2025-64459 (Django SQLi) &amp; CVE-2025-24893 (XWiki RCE). We've automatically updated to Block—stay secure! 🚀 https://developers.cloudflare.com/changelog/2026-02-02-waf-release/

    Post summary

    Cloudflare’s latest WAF update adds detection and blocking rules for CVE‑2025‑64459 (Django SQLi) and CVE‑2025‑24893 (XWiki RCE), providing immediate protection against these critical vulnerabilities.

    0000062
    1 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appxwikixwiki---
Appxwikixwiki5.3--
Appxwikixwiki5.3--
Appxwikixwiki5.3--

Explore more