CVE-2025-66474 | xwiki xwiki-rendering up to 16.10.9/17.4.2/17.6.0-rc-0 eval injection (GHSA-9xc6-c2rm-f27p / WID-SEC-2025-2815)
A vulnerability marked as critical has been reported in xwiki xwiki-rendering up to 16.10.9/17.4.2/17.6.0-rc-0. This impacts an unknown function. This manipulation causes improper neutralization of directives in dynamically evaluated code.
This vulnerability appears as CVE-2025-66474. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.