PT-2025-30912 · Xwiki · Xwiki

·

CVE-2025-54385

·

Published

2025-07-25

·

Updated

2025-07-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xWiki versions prior to 16.10.6 xWiki versions prior to 17.3.0-rc-1
Description The application allows execution of arbitrary SQL queries in Oracle databases using functions like DBMS XMLGEN or DBMS XMLQUERY. The XWiki#searchDocuments API does not sanitize queries, and Hibernate allows the use of native functions within HQL queries.
Recommendations Upgrade to xWiki version 16.10.6 or later. Upgrade to xWiki version 17.3.0-rc-1 or later.

Exploit

Fix

DoS

SQL injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13439
CVE-2025-54385
GHSA-P9QM-P942-Q3W5

Affected Products

Xwiki