CVE-2025-55728 | xwikisas xwiki-pro-macros up to 1.26.4 classes eval injection (GHSA-48f4-h726-74p5)
A vulnerability labeled as very critical has been found in xwikisas xwiki-pro-macros up to 1.26.4. Impacted is an unknown function. Such manipulation of the argument classes leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is listed as CVE-2025-55728. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.