Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Akka introduces platform for distributed agentic AI

      July 14, 2025

      Design Patterns For AI Interfaces

      July 14, 2025

      Amazon launches spec-driven AI IDE, Kiro

      July 14, 2025

      This week in AI dev tools: Gemini API Batch Mode, Amazon SageMaker AI updates, and more (July 11, 2025)

      July 11, 2025

      Windows 11 will soon be able to describe images on your screen using AI — and it’ll all be done locally

      July 15, 2025

      Marvel Rivals’ swimsuit lineup kicks off this week — with hot new outfits for these characters

      July 15, 2025

      iPhone alarm not going off? 6 potential fixes to this annoying issue

      July 15, 2025

      ChatGPT falls for another Windows license key scam — generating valid codes in a guessing game after a researcher “gives up”

      July 14, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The details of TC39’s last meeting

      July 15, 2025
      Recent

      The details of TC39’s last meeting

      July 15, 2025

      Modern async iteration in JavaScript with Array.fromAsync()

      July 14, 2025

      Vite vs Webpack: A Guide to Choosing the Right Bundler

      July 14, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Windows 11 will soon be able to describe images on your screen using AI — and it’ll all be done locally

      July 15, 2025
      Recent

      Windows 11 will soon be able to describe images on your screen using AI — and it’ll all be done locally

      July 15, 2025

      Marvel Rivals’ swimsuit lineup kicks off this week — with hot new outfits for these characters

      July 15, 2025

      The Curious Case of AUR Updates Fetching 30 GB of Data for Electron

      July 14, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-53836 – XWiki Rendering Macro Execution Bypass

    CVE-2025-53836 – XWiki Rendering Macro Execution Bypass

    July 15, 2025

    CVE ID : CVE-2025-53836

    Published : July 15, 2025, 12:15 a.m. | 2 hours, 14 minutes ago

    Description : XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn’t preserve the restricted attribute of the transformation context when executing nested macros. This allows executing macros that are normally forbidden in restricted mode, in particular script macros. The cache and chart macros that are bundled in XWiki use the vulnerable feature. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. To avoid the exploitation of this bug, comments can be disabled for untrusted users until an upgrade to a patched version has been performed. Note that users with edit rights will still be able to add comments via the object editor even if comments have been disabled.

    Severity: 9.9 | CRITICAL

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-53839 – DRACOON Branding Service Cross-Site Scripting Vulnerability
    Next Article Marvel Rivals’ swimsuit lineup kicks off this week — with hot new outfits for these characters

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-53643 – AIOHTTP Request Smuggling Vulnerability

    July 15, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-53819 – Nix Privilege Escalation Vulnerability

    July 15, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Chrome to introduce Keyboard Shrotcuts for Tab Groups

    Operating Systems

    PoC Exploit Released for Fortinet 0-Day Vulnerability that Allows Remote Code Execution

    Security

    These old iPhones, Macs, and iPads won’t run Apple’s latest updates – did yours make the cut?

    News & Updates

    Learn Vue.js in This Beginner’s Course

    Development

    Highlights

    IT Expense Reimbursement Policy

    April 7, 2025

    Use this policy to ensure all IT expenses are properly reported, processed, and reimbursed. Customizable…

    CVE-2025-49454 – LoftOcean TinySalt PHP Remote File Inclusion Vulnerability

    June 10, 2025

    Markus Buehler receives 2025 Washington Award

    June 8, 2025

    Senator Chides FBI for Weak Advice on Mobile Security

    June 30, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.