PT-2025-50549 · Xwiki · Xwiki

Michitux

·

Published

2025-07-04

·

Updated

2025-12-19

·

CVE-2025-66473

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XWiki versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3, and 17.5.0-rc-1 through 17.6.0
Description The XWiki platform contains a REST API that does not limit the number of items requested in a single request. This can cause performance issues, including slowness and unavailability, particularly when requesting a large number of pages. The /rest/wikis/xwiki/spaces API endpoint is an example, as it returns all spaces (pages) on the wiki by default.
Recommendations Update to XWiki version 17.4.4 or later. Update to XWiki version 16.10.11 or later.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-15981
CVE-2025-66473
GHSA-CC84-Q3V3-MHGF

Affected Products

Xwiki