Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-24893 — PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893) | Kitploit
Tools/GitHubGitHub/cmassa/cve-2025-24893
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubcmassa/cve-2025-24893

CVE-2025-24893

PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-24893 - XWiki Unauthenticated Remote Code Execution

PoC exploit for XWiki Unauthenticated Remote Code Execution Vulnerability (CVE-2025-24893). This PoC allows to execute arbitrary commands through Groovy code on SolrSearch Macro.

Details

root@kitploit:~
Severity: Critical
CVSS Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
EPSS Score: 92.01% (Very high likelihood of exploitation)
Affected Versions: All versions prior to 15.10.11, 16.4.1, and 16.5.0RC1
Patched Versions: 15.10.11, 16.4.1, 16.5.0RC1

Usage

root@kitploit:~
usage: CVE-2025-24893 [-h] [-t TARGET] [-c COMMAND] [-v]

Unauthenticated Remote Code Execution (RCE) on XWiki

options:
  -h, --help            show this help message and exit
  -t, --target TARGET   Target XWiki URL
  -c, --command COMMAND Command to execute
  -v, --verify          Verify if target XWiki is vulnerable

Example

Verification

verification

Basic command exploitation

exploitation

Remote shell exploitation

remote_shell

References

[https://www.offsec.com/blog/cve-2025-24893/] [https://nvd.nist.gov/vuln/detail/CVE-2025-24893] [https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2025-24893]

Disclaimer

This exploit code is provided for educational and authorized testing purposes only. Do not use this code against any system without explicit permission from the owner. The author assumes no responsibility for any misuse or damage caused by this program.

Download Tool