CVE-2025-24893 is a critical remote code execution (RCE) vulnerability affecting XWiki Platform versions prior to 15.10.11, 16.4.1, and 16.5.0RC1. This flaw allows any unauthenticated guest to execute arbitrary code by sending a crafted request to the SolrSearch component, severely impacting the confidentiality, integrity, and availability of the XWiki installation. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. It is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and reports of the RondoDox botnet leveraging it, with multiple public exploit modules and templates available. The vulnerability has garnered significant community discussion and media coverage due to its severity and active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4, < 15.10.11CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 16.0.0, < 16.4.1CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
5.3CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:5.3:-:*:*:*:*:*:* | ||
5.3CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:5.3:milestone2:*:*:*:*:*:* | ||
5.3CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:5.3:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.