Any guest can perform arbitrary remote code execution through a request to SolrSearch. This impacts the confidentiality, integrity, and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 15.10.11, 16.4.1, and 16.5.0RC1.
id: CVE-2025-24893
info:
name: XWiki Platform - Remote Code Execution
author: iamnoooob,rootxha
...