Medium severity6.8NVD Advisory· Published Nov 19, 2025· Updated Jun 17, 2026
CVE-2025-65089
CVE-2025-65089
Description
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.xwiki.pro:xwiki-pro-macros-uiMaven | < 1.27.0 | 1.27.0 |
Affected products
3cpe:2.3:a:xwiki:pro_macros:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:xwiki:pro_macros:*:*:*:*:*:*:*:*range: <1.27.0
- (no CPE)range: < 1.27.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-8c52-x9w7-vc95ghsaADVISORY
- github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-8c52-x9w7-vc95nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-65089ghsaADVISORY
News mentions
0No linked articles in our index yet.