Moderate severityNVD Advisory· Published Nov 19, 2025· Updated Nov 19, 2025
XWiki view file macro: User can view content of office file without view rights on the attachment
CVE-2025-65089
Description
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.xwiki.pro:xwiki-pro-macros-uiMaven | < 1.27.0 | 1.27.0 |
Affected products
2- Range: < 1.27.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-8c52-x9w7-vc95ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-65089ghsaADVISORY
- github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-8c52-x9w7-vc95ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.