CVE-2025-66474 is a critical vulnerability affecting XWiki Rendering versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2, and 17.5.0-rc-1 through 17.5.0. It allows authenticated users with editing privileges to achieve Remote Code Execution (RCE) due to insufficient protection against {{/html}} injection. With a CVSS score of 8.8 (High), this vulnerability has a low attack complexity and can lead to full compromise of the wiki, including unrestricted read/write access and arbitrary script execution. While no public exploits or active exploitation have been observed, and community discussion is minimal, organizations should prioritize patching to versions 16.10.10, 17.4.3, or 17.6.0-rc-1 to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.10.10CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:* | ||
>= 17.0.0, < 17.4.3CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:* | ||
17.5.0CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki-rendering:17.5.0:-:*:*:*:*:*:* | ||
17.5.0CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki-rendering:17.5.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.