CVE-2025-24893
EPSS Score
Source: FIRST.org · 2026-05-23CVSS v3.1
Source: VulnerabilityLookup (CIRCL)Description
VulnerabilityLookup (CNA)Affected Products
Attack Intelligence
Exploits & PoC
PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.
CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper
XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)
PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronou
This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSear
this is a poc for the CVE-2025-24893
Modified exploit for CVE-2025-24893
POC exploit for CVE-2025-24893
PoC for CVE-2025-24893
Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell.
CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform.
Some poorly crafted exploit scripts
XWiki Unauthenticated RCE Exploit for Reverse Shell
Proof of Concept for CVE-2025-24893 demonstrating unauthenticated remote command execution in XWiki through unsafe server-side template evaluation.
Reverse Shell Payload for CVE-2025-24893
This is a small script for the rce vulnerability for CVE-2025-24893. It supports basic input/output
PoC | XWiki Platform 15.10.10 - Remote Code Execution
Proof-of-Concept exploit for CVE-2025-24893, an unauthenticated Remote Code Execution (RCE) vulnerability in XWiki. Exploits a template injection fla
Bash POC script for RCE vulnerability in XWiki Platform
XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC
A POC for CVE-2025-24893 written in python
PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)
A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
CVE-2025-24893 RCE exploit for XWiki with reverse shell capability
Unauthenticated RCE exploit for XWiki CVE-2025-24893 via Groovy script injection
CVE-2025-24893 | Vulnérabilité d'exécution de code à distance sur la plateforme XWiki (preuve de concept)
CVE-2025-24893 – XWiki SSTI unauthenticated RCE exploit (HackTheBox CTF)