PT-2025-35831 · Xwiki · Xwiki Platform

Tmortagne

·

Published

2025-09-03

·

Updated

2025-10-17

·

CVE-2025-55747

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 6.1-milestone-2 through 16.10.6
Description The XWiki Platform is a generic wiki platform. Affected versions allow access to configuration files through the webjars API. This issue is resolved in version 16.10.7.
Recommendations Update to version 16.10.7 or later.

Exploit

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

BDU:2025-13434
CVE-2025-55747
GHSA-QWW7-89XH-X7M7

Affected Products

Xwiki Platform