CVE-2025-24893
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.86% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-10-30
- Nuclei
- critical · CWE-95
- Published
- 2025-02-20
- Updated
- 2026-02-26
Proof-of-concept exploits (46)
- https://jira.xwiki.org/browse/XWIKI-22149
- 0xVoodoo/PoCs0★ · 2026-05-01
- 570RMBR3AK3R/xwiki-cve-2025-24893-poc3★ · 2025-08-06
- AliElKhatteb/CVE-2024-32019-POC5★ · 2025-08-03
- Artemir7/CVE-2025-24893-EXP2★ · 2025-05-05
- AzureADTrent/CVE-2025-24893-Reverse-Shell0★ · 2025-08-03
- Bishben/xwiki-15.10.8-reverse-shell-cve-2025-248930★ · 2025-09-10
- CMassa/CVE-2025-248930★ · 2025-08-15
- D3Ext/CVE-2025-248934★ · 2025-08-09
- Hex00-0x4/CVE-2025-24893-XWiki-RCE6★ · 2025-08-08
- IIIeJlyXaKapToIIIKu/CVE-2025-24893-XWiki-unauthenticated-RCE-via-SolrSearch1★ · 2025-08-07
- Infinit3i/CVE-2025-248936★ · 2025-09-02
- JacintaSyilloam/exploit-scripts0★ · 2025-09-24
- Retro023/CVE-2025-24893-POC0★ · 2026-01-26
- Th3Gl0w/CVE-2025-24893-POC1★ · 2025-08-09
- The-Red-Serpent/CVE-2025-248930★ · 2025-08-08
- alaxar/CVE-2025-248930★ · 2025-08-08
- andwati/CVE-2025-248930★ · 2025-09-05
- b0ySie7e/CVE-2025-2489311★ · 2025-09-03
- dhiaZnaidi/CVE-2025-24893-PoC0★ · 2025-08-03
- dollarboysushil/CVE-2025-24893-XWiki-Unauthenticated-RCE-Exploit-POC17★ · 2025-08-04
- gunzf0x/CVE-2025-2489322★ · 2025-08-22
- hackersonsteroids/cve-2025-248935★ · 2025-08-03
- iSee857/CVE-2025-24893-PoC10★ · 2025-04-01
- investigato/cve-2025-24893-poc0★ · 2025-08-07
- mah4nzfr/CVE-2025-248930★ · 2025-08-31
- saad0x1/Exploits1★ · 2025-09-07
- torjan0/xwiki_solrsearch-rce-exploit2★ · 2025-11-29
- x0da6h/POC-for-CVE-2025-248931★ · 2025-09-20
- zs1n/CVE-2025-248930★ · 2025-08-05
- 0xDTC/XWiki-Platform-RCE-CVE-2025-24893
- 80Ottanta80/CVE-2025-24893-PoC
- BreakingRohit/CVE-2025-24893-PoC
- Fomovet/cve-2025-24893
- TomKingori/xwiki-cve-2025-24893-exploit
- Y2F05p2w/CVE-2025-24893
- Yukik4z3/CVE-2025-24893
- endusdksla/xwiki-cve-2025-24893
- gmh5225/CVE-2025-24893-RCE-PoC
- gotr00t0day/CVE-2025-24893
- hasecto/CVE-2025-24893
- kimtangker/CVE-2025-24893
- nohack1212/CVE-2025-24893-
- o0wo0o/CVE-2025-24893_Shell
- rippsec/CVE-2025-24893-XWiki-SSTI-RCE
- vasilysaint/CVE-2025-24893