CVE-2025-65089

MEDIUM

Xwiki Pro Macros < 1.27.0 - Missing Authorization

Title source: rule

Description

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.

Scores

CVSS v3 6.8
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

Classification

CWE
CWE-862
Status published

Affected Products (2)

xwiki/pro_macros < 1.27.0
com.xwiki.pro/xwiki-pro-macros-ui < 1.27.0Maven

Timeline

Published Nov 19, 2025
Tracked Since Feb 18, 2026