
A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
CVE-2025-24893 is a critical unauthenticated Remote Code Execution (RCE) vulnerability in XWiki, a widely used open-source enterprise wiki platform.
The flaw exists in the SolrSearch macro, which improperly evaluates Groovy expressions embedded in search queries.
This vulnerability allows remote, unauthenticated attackers to execute arbitrary Groovy code on the server, potentially gaining full control of the affected system.
15.10.1116.4.116.5.0RC115.10.1116.4.116.5.0RC1I’ve completed multiple certifications, including:
I’m also an active bug bounty hunter and top-ranked participant on platforms like TryHackMe and Hack The Box, where I currently rank in the top 1%.
I'm passionate about helping others learn ethical hacking through hands-on labs and mentoring.