CVE-2025-55728 is a critical remote code execution (RCE) vulnerability affecting XWiki Remote Macros versions 1.0 through 1.26.4. The flaw stems from insufficient escaping of the 'classes' parameter within the panel macro, allowing XWiki syntax injection by any user with page editing privileges. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a network-exploitable, low-complexity attack with high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion. Organizations using affected XWiki Remote Macros versions should upgrade to 1.26.5 immediately to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0, < 1.26.5CPE matchmatch criteria | cpe:2.3:a:xwiki:pro_macros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.