XWiki Platform — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
October 30, 2025
Last Seen
November 17, 2025

Related Threat Clusters

  • RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Vulnerability

    The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable,…

    3 articles · Updated November 17, 2025
  • RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Flaw

    The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers,…

    5 articles · Updated November 17, 2025
  • CISA Adds Multiple Vulnerabilities to KEV Catalog

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities from Apple, Gladinet CentreStack, Triofox, and CWP Control Web Panel to its Known Exploited Vulnerabilities (KEV) catalog. These…

    5 articles · Updated December 15, 2025
  • CISA Adds XWiki and VMware Vulnerabilities to KEV Catalog

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to the XWiki Platform and Broadcom's VMware Aria Operations and VMware Tools to its Known Exploited Vulnerabilities…

    2 articles · Updated October 31, 2025
  • CISA Updates KEV Catalog with XWiki and VMware Vulnerabilities

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to the XWiki Platform and Broadcom's VMware Aria Operations and VMware Tools to its Known Exploited Vulnerabilities…

    2 articles · Updated October 31, 2025

Recent Intelligence Reports

  • RondoDox botnet malware now hacks servers using XWiki flaw — Bleepingcomputer · November 17, 2025
  • RondoDox expands botnet by exploiting XWiki RCE bug left unpatched since February 2025 — Securityaffairs.Co · November 17, 2025
  • U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog — Securityaffairs.Co · November 5, 2025
  • U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalog — Securityaffairs.Co · October 30, 2025

CVSS v3.1 Breakdown