PT-2025-25430 · Xwiki · Xwiki

Simon Urli

·

Published

2025-06-13

·

Updated

2025-09-03

·

CVE-2025-49580

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XWiki versions 7.4.5 through 16.4.7 XWiki versions 8.2 through 16.10.4 XWiki versions 17.1.0-rc-1 and earlier
Description The issue allows pages to gain script or programming rights when they contain a link and the target of the link is renamed or moved, potentially leading to the execution of scripts contained in xobjects that should not have been executed.
Recommendations For XWiki versions 7.4.5 through 16.4.7, update to version 16.4.7 or later. For XWiki versions 8.2 through 16.10.4, update to version 16.10.4 or later. For XWiki versions 17.1.0-rc-1 and earlier, update to version 17.1.0-rc-1 or later.

Exploit

Fix

LPE

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2025-13440
CVE-2025-49580
GHSA-JM43-HRQ7-R7W6

Affected Products

Xwiki