S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Nov 14, 2025

CVE-2025-51991 Scanner

CVE-2025-51991 Scanner - Server Side Template Injection (SSTI) vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-51991
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity template code, which is rendered on the server side without proper validation or sandboxing. This enables the execution of arbitrary template logic, which may expose internal server information or, in specific configurations, lead to further exploitation such as remote code execution or sensitive data leakage. The vulnerability resides in improper handling of dynamic template rendering within user-supplied configuration fields.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 9, 2026View on NVD →
Detail

The XWiki software serves as a powerful open-source wiki platform typically used by organizations and individuals for document management, knowledge sharing, and collaboration. It allows users to create and edit web pages collectively in a simple yet feature-rich environment. Trusted by large companies, educational institutions, and community projects, XWiki offers robust functionalities suitable for various administrative and organizational tasks. It is highly customizable, empowering administrators to enforce various configurations and integrations with external systems. The software supports multiple extensions and is built on top of Java EE technologies, making it a versatile choice for both small and large enterprises.

Server Side Template Injection (SSTI) is a critical vulnerability that arises when user input is not correctly validated and is processed within server-side template systems. This can possibly lead to arbitrary code execution on the server when a threat actor inputs malicious payloads. Specifically, in the case of XWiki, this vulnerability occurs within the Administration interface HTTP Meta Info field, allowing authenticated administrators to run unauthorized template code. SSTIs can lead to server compromise, data exposure, and further attack vectors if not mitigated promptly.

The vulnerability within XWiki lies in the improper validation of Apache Velocity template code in the Administration interface HTTP Meta Info field, allowing template injections. This endpoint, accessible by authenticated users with administrative privileges, is intended for managing presentation settings of the XWiki application. However, lacking input sanitation permits exploitation through crafted input like `%23set%28%24x%3D7%2A7%29%24x`, which is executed within the server. Successful exploitation may lead to outputs that expose internal server states or unintended functions executed on the server, posing significant security risks.

When exploited, this vulnerability can cause severe impacts on system confidentiality, integrity, and availability. Attackers may execute arbitrary server-side code, leading potentially to unauthorized access to sensitive information stored within the server. This breach could further enable remote code execution, allowing an adversary to control the server environment. As a result, it may lead to data breaches, systems being added to botnets, or significant business disruption if critical services are compromised. Prompt mitigation is necessary to prevent such adverse outcomes.

REFERENCES

Solution Advice
  • Update XWiki to a version later than 17.3.0 to mitigate the Server Side Template Injection vulnerability.
  • Regularly review and sanitize input fields to prevent unauthorized execution of template logic.
  • Enforce strict access control to administrative interfaces to limit potential exploitation by malicious entities.
  • Conduct thorough security audits and penetration testing to detect any residual vulnerabilities.
  • Implement web application firewalls to monitor and block suspicious activities targeting template injection points.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.