PT-2025-18295 · Xwiki · Xwiki

CVE-2025-32974

·

Published

2024-03-19

·

Updated

2025-05-13

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki versions 15.9-rc-1 through 15.10.7 XWiki versions 16.0.0-rc-1 through 16.1.x
Description The issue concerns a generic wiki platform where the required rights analysis does not consider TextAreas with default content type. This allows a user to put malicious scripts in certain properties that will be executed after a user with script, admin, or programming rights edited the page. Such a malicious script could impact the confidentiality, integrity, and availability of the whole XWiki installation.
Recommendations For XWiki versions 15.9-rc-1 through 15.10.7, update to version 15.10.8 to resolve the issue. For XWiki versions 16.0.0-rc-1 through 16.1.x, update to version 16.2.0 to resolve the issue.

Exploit

Fix

DoS

LPE

Improper Privilege Management

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05354
CVE-2025-32974
GHSA-MVGM-3RW2-7J4R

Affected Products

Xwiki