GHSA-w3wh-g4m9-783p · Severity: critical · Ecosystem: maven — XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 and prior to version 14.10, the XHTML syntax depended on the `xdom+xml/current` syntax which allows the creation of raw blocks that permit the insertion of arbitrary HTML content including JavaScript. This allows XSS attacks for users who can edit a document like their user profile (enabled by default). This has been fixed in version 14.10 by removing the dependency on the `xdom+xml/current` syntax from the XHTML syntax. Note that the `xdom+xml` syntax is still vulnerable to this attack. As it's main purpose is testing and its use is quite difficult, this syntax shouldn't be installed or used on a regular wiki. There are no known workarounds apart from upgrading.
Conclusion & alert: CVE-2025-53835 is rated High Risk (69/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.85%). Core evidence: EPSS rose +2.11% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-10 | 1.74% | 3.85% | +2.11% |
| 2 | 2026-04-30 | 1.60% | 1.74% | +0.13% |
| 3 | 2026-04-09 | — | 1.60% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
GHSA-w3wh-g4m9-783p · Severity: critical · Ecosystem: maven — XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
| URL | Tags |
|---|---|
| https://github.com/xwiki/xwiki-rendering/commit/a4ca31f99f524b9456c64150d6f375984aa81ea7 | Patch |
| https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-w3wh-g4m9-783p | Patch Third Party Advisory |
| https://jira.xwiki.org/browse/XRENDERING-660 | Issue Tracking |