PT-2025-18295 · Xwiki · Xwiki

Published

2024-03-19

·

Updated

2025-05-13

·

CVE-2025-32974

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki versions 15.9-rc-1 through 15.10.7 XWiki versions 16.0.0-rc-1 through 16.1.x
Description The issue concerns a generic wiki platform where the required rights analysis does not consider TextAreas with default content type. This allows a user to put malicious scripts in certain properties that will be executed after a user with script, admin, or programming rights edited the page. Such a malicious script could impact the confidentiality, integrity, and availability of the whole XWiki installation.
Recommendations For XWiki versions 15.9-rc-1 through 15.10.7, update to version 15.10.8 to resolve the issue. For XWiki versions 16.0.0-rc-1 through 16.1.x, update to version 16.2.0 to resolve the issue.

Exploit

Fix

LPE

Improper Privilege Management

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

BDU:2025-05354
CVE-2025-32974
GHSA-MVGM-3RW2-7J4R

Affected Products

Xwiki