Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8c52-x9w7-vc95 | XWiki view file macro: User can view content of office file without view rights on the attachment |
Thu, 15 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki pro Macros |
|
| CPEs | cpe:2.3:a:xwiki:pro_macros:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xwiki
Xwiki pro Macros |
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwikisas
Xwikisas xwiki-pro-macros |
|
| Vendors & Products |
Xwikisas
Xwikisas xwiki-pro-macros |
Wed, 19 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0. | |
| Title | XWiki view file macro: User can view content of office file without view rights on the attachment | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-19T18:46:46.790Z
Reserved: 2025-11-17T20:55:34.690Z
Link: CVE-2025-65089
Updated: 2025-11-19T18:46:33.831Z
Status : Analyzed
Published: 2025-11-19T18:15:51.487
Modified: 2026-01-15T17:54:44.807
Link: CVE-2025-65089
No data.
OpenCVE Enrichment
Updated: 2025-11-21T09:16:19Z
Github GHSA