Improper privilege management in XWiki platform - CVE-2025-49581
Published: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper privilege management in wiki macro wiki-type parameters when processing default parameter values in a wiki macro used by a document with programming rights. A remote user can define or override a wiki macro with a crafted default parameter value to execute arbitrary code.
Exploitation requires edit rights on a page and can lead to execution with the programming rights of the author of the document where the macro is used.