Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-24893 — A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint. | Kitploit
Tools/GitHubGitHub/ibadovulfat/cve-2025-24893
Vulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationLabs & Practice
GitHubibadovulfat/cve-2025-24893

CVE-2025-24893

A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.

View Repository
8 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-24893 – XWiki Remote Code Execution (RCE)

Overview

CVE-2025-24893 is a critical unauthenticated Remote Code Execution (RCE) vulnerability in XWiki, a widely used open-source enterprise wiki platform.
The flaw exists in the SolrSearch macro, which improperly evaluates Groovy expressions embedded in search queries.

This vulnerability allows remote, unauthenticated attackers to execute arbitrary Groovy code on the server, potentially gaining full control of the affected system.


Vulnerability Details

  • CVE ID: CVE-2025-24893
  • Severity: Critical
  • CVSS v3.1 Score: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  • EPSS Score: 92.01% (Very high likelihood of exploitation)
  • Published: February 20, 2025

Affected Versions

  • All versions prior to:
    • 15.10.11
    • 16.4.1
  • 16.5.0RC1
  • Patched Versions

    • 15.10.11
    • 16.4.1
    • 16.5.0RC1

    About Me

    I’ve completed multiple certifications, including:

    • Certified Ethical Hacker (CEH & CEH Practical)
    • Web Application Hacking and Security (W|AHS)
    • Certified Cybersecurity Technician (C|CT)
    • Certified Penetration Testing Specialist (CPTS – HTB Academy)
    • Certified Penetration Testing Specialist (BBH – HTB Academy)
    • Certified Penetration Testing Professional (CPENT – AI) – Currently in Preparation

    I’m also an active bug bounty hunter and top-ranked participant on platforms like TryHackMe and Hack The Box, where I currently rank in the top 1%.

    I'm passionate about helping others learn ethical hacking through hands-on labs and mentoring.

    Connect with Me

    • LinkedIn
    • Portfolio
    Download Tool