CVE-2025-65089

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.
Configurations

No configuration.

History

19 Nov 2025, 19:15

Type Values Removed Values Added
References () https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-8c52-x9w7-vc95 - () https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-8c52-x9w7-vc95 -

19 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 18:15

Updated : 2025-11-19 19:15


NVD link : CVE-2025-65089

Mitre link : CVE-2025-65089

CVE.ORG link : CVE-2025-65089


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization