PT-2025-30912 · Xwiki · Xwiki

Thomas Mortagne

·

Published

2025-07-25

·

Updated

2025-07-26

·

CVE-2025-54385

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xWiki versions prior to 16.10.6 xWiki versions prior to 17.3.0-rc-1
Description The application allows execution of arbitrary SQL queries in Oracle databases using functions like DBMS XMLGEN or DBMS XMLQUERY. The XWiki#searchDocuments API does not sanitize queries, and Hibernate allows the use of native functions within HQL queries.
Recommendations Upgrade to xWiki version 16.10.6 or later. Upgrade to xWiki version 17.3.0-rc-1 or later.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-13439
CVE-2025-54385
GHSA-P9QM-P942-Q3W5

Affected Products

Xwiki