Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
XWiki

XWiki Vendor Cyber Rating & Cyber Score

xwiki.com

Founded in 2004, XWiki is the leading provider of professional open-source solutions and consultancy for knowledge management and collaborative platforms. Planning to move to XWiki? Check our alternatives page: https://xwiki.com/en/Alternatives. Trusted by @Amazon, @Lenovo, @CNFPT, @Naval-group, and many more.


XWiki A.I CyberSecurity Scoring

XWiki
Company Information
Website:http://www.xwiki.com
Employees number:76
Number of followers:4,455
NAICS:5112
Industry Type:Software Development
Homepage:xwiki.com
XWiki Risk Score (AI oriented)
Between 700 and 749
logo
XWikiSoftware Development
Updated:
04/04/2026
748/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
XWiki Global Score (TPRM)
xxxx
logo
XWikiSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

XWiki
XWikiModerate
Current Score
748Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
749Before Incident
APRIL 2026
749Before Incident
MARCH 2026
748Before Incident
FEBRUARY 2026
748Before Incident
JANUARY 2026
748Before Incident
DECEMBER 2025
747Before Incident
NOVEMBER 2025
752Before Incident
Vulnerability
31 Oct 2025XWiki
XWiki Platform (Open-Source Organizations)

Critical Eval Injection Vulnerability in XWiki Platform (CVE-2025-24893)

747After Incident
CRITICAL-5
XWI2092520103125
The CVE-2025-24893 vulnerability in XWiki Platform’s SolrSearch component allows unauthenticated guest users to execute arbitrary remote code via eval injection (CWE-95), bypassing all security controls. Exploiting this flaw grants attackers full command execution privileges equivalent to the web server process, enabling data exfiltration, malware deployment, lateral movement, and persistent network compromise. Organizations using XWiki for collaboration or public-facing wikis are at acute risk, as the flaw weaponizes the platform’s trust model. CISA has issued an urgent directive with a November 20, 2025, remediation deadline, mandating immediate patching or complete discontinuation of XWiki if patching is infeasible. The CVSS 9.8 (Critical) severity reflects the vulnerability’s low attack complexity and network-based exploitation potential. While no active ransomware campaigns are confirmed, the flaw’s accessibility and severity make it a prime target for rapid weaponization by advanced threat actors. Failure to remediate risks system takeover, sensitive data exposure, and operational disruption, with cloud deployments subject to additional compliance mandates under BOD 22-01.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationRemote Code Execution (RCE)Eval Injection
IMPACT
XWiki Platform deployments (development, testing, production environments)Potential exfiltration of sensitive organizational dataDeployment of malware payloadsPersistent network footholds for lateral movementComplete compromise of system integrity and data confidentialityHigh risk due to potential data breaches and system compromise
DATA BREACH
Potential risk if exploited
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
752Before Incident
JULY 2025
752Before Incident
JUNE 2023
751Before Incident
Vulnerability
16 Jun 2023XWiki
XWiki

Widespread Exploitation of Critical XWiki Vulnerability (CVE-2025-24893)

748After Incident
CRITICAL-3
XWI0133201111725
Cybersecurity researchers identified a critical Remote Code Execution (RCE) vulnerability (CVE-2025-24893) in XWiki, actively exploited by multiple threat actors, including botnets (e.g., RondoDox), cryptocurrency miners, and advanced attackers deploying reverse shells. The vulnerability, first exploited on October 28, 2025, escalated rapidly, with CISA adding it to the KEV catalog just two days later. Attackers leveraged the flaw to compromise servers globally, deploying malware, coin miners (e.g., payload hash *03a77a556f074184b254d90e13cdd3a31efaa5a77640405e5f78aa462736acf7*), reverse shells (via AWS IPs like *18.228.3.32*), and persistence mechanisms. Scanning operations (e.g., via Nuclei templates) targeted vulnerable installations, attempting to exfiltrate sensitive data (e.g., /etc/passwd). The attack chain involved compromised infrastructure (e.g., QNAP/DrayTek devices via CVE-2023-47218), indicating layered exploitation. The speed of weaponization—from isolated exploits to widespread botnet integration (RondoDox by November 3)—left defenders with minimal time to patch, risking large-scale server takeovers, data breaches, and operational disruption for organizations relying on XWiki for collaboration or documentation.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationBotnet IntegrationCryptojackingReverse Shell AttacksAutomated Scanning
MOTIVATION
Financial Gain (Cryptojacking)Botnet ExpansionPersistence/Access BrokerageReconnaissancePotential Data Theft
IMPACT
Systems Affected: Global XWiki servers (exact count unknown)Potential server compromisesUnauthorized resource usage (CPU/memory for mining)Backdoor persistencePotential reputational damage for XWiki and affected organizations
DATA BREACH
/etc/passwd (attempted access)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for XWiki ?
?
What was XWiki's A.I Rankiteo Cyber Score in May 2026 ?
?
What was XWiki's A.I Rankiteo Cyber Score in April 2026 ?
?
What was XWiki's A.I Rankiteo Cyber Score in March 2026 ?
?
What was XWiki's A.I Rankiteo Cyber Score in February 2026 ?
?
What was XWiki's A.I Rankiteo Cyber Score in January 2026 ?
?
What was XWiki's A.I Rankiteo Cyber Score in December 2025 ?
?
What was XWiki's A.I Rankiteo Cyber Score in November 2025 ?
?
What was XWiki's A.I Rankiteo Cyber Score in October 2025 ?
?
What was XWiki's A.I Rankiteo Cyber Score in September 2025 ?
?
What was XWiki's A.I Rankiteo Cyber Score in August 2025 ?
?
What was XWiki's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on XWiki's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with XWiki ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view XWiki's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?