<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — XWiki</title><description>Actively exploited vulnerabilities affecting XWiki products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/xwiki.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-24893 — XWiki Platform Eval Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-24893</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-24893</guid><description>This vulnerability in XWiki Platform allows completely unauthenticated visitors — including anonymous internet users — to inject and execute arbitrary code on the server by crafting a malicious request to the SolrSearch endpoint. Because no login is required, the attack surface is wide open to anyone who can reach the instance. Successful exploitation gives an attacker remote code execution, meaning full control over the underlying server and any data it holds.</description><pubDate>Thu, 30 Oct 2025 00:00:00 GMT</pubDate><category>XWiki</category><category>Platform</category></item></channel></rss>