XWiki <= 17.3.0 contains a server-side template injection caused by improper validation of Apache Velocity template code in the Administration interface HTTP Meta Info field, letting authenticated administrators execute arbitrary template logic.
id: CVE-2025-51991
info:
name: XWiki <= 17.3.0 - Server-Side Template Injection (SSTI)
author:
...