{"id":"CVE-2025-49586","aliases":["GHSA-jp4x-w9cj-97q7"],"url":"https://o3.security/vulnerability/CVE-2025-49586","summary":"XWiki allows remote code execution through preview of XClass changes in AWM editor","details":"XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.","published":"2025-06-13T17:47:07.105Z","modified":"2026-08-08T09:05:46.061763Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"16.4.7"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"16.10.3"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"17.0.0"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/ef978315649cf83eae396021bb33603a1a5f7e42","label":"xwiki/xwiki-platform@ef97831"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-22719"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49586.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jp4x-w9cj-97q7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49586"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/ef978315649cf83eae396021bb33603a1a5f7e42"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T09:05:46.061763Z"}}