CVE-2025-24893

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
93.75%
probability
This CVE has a 93.75% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

gunzf0x/CVE-2025-24893

PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.

20
dollarboysushil/CVE-2025-24893-XWiki-Unauthenticated-RCE-Exploit-POC

CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper

16
b0ySie7e/CVE-2025-24893

PoC CVE-2025-24893 — b0ySie7e/CVE-2025-24893

11
iSee857/CVE-2025-24893-PoC

XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)

10
Hex00-0x4/CVE-2025-24893-XWiki-RCE

This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSear

6
Infinit3i/CVE-2025-24893

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronou

6
hackersonsteroids/cve-2025-24893

Modified exploit for CVE-2025-24893

5
AliElKhatteb/CVE-2024-32019-POC

this is a poc for the CVE-2025-24893

5
D3Ext/CVE-2025-24893

POC exploit for CVE-2025-24893

4
nopgadget/CVE-2025-24893

PoC CVE-2025-24893 — nopgadget/CVE-2025-24893

3
10 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 93.75%
Mentions 3
Last Seen Jan 01, 2026

CNA Information

Analyst Note

CVE-2025-24893 shows clear zero-day characteristics: published 2025-02-20, actively exploited in the wild by RondoDox botnet targeting unpatched XWiki instances within weeks of disclosure, and explicitly named in CISA alerts as 'under attack'. The very short window between publication and documented exploitation, combined with critical CVSS 9.8 severity and active threat actor targeting, confirms zero-day status.

Threat Actors 5

Cobalt
apt_group Financial crime 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
Red October
apt_group 🇷🇺 RU
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN

Triage Info

Decided atMar 05, 2026