Skip to content

Known CVE

XWiki <= 17.3.0 - Server-Side Template Injection (SSTI)

XWiki <= 17.3.0 contains a server-side template injection caused by improper validation of Apache Velocity template code in the Administration interface HTTP Meta Info field, letting authenticated administrators execute arbitrary template logic.

CVE-2025-51991

Critical2025CVSS 9.1CWE-94

xwiki · ssti · template-injection · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website