CVE-2025-29925: high-severity vulnerability in xwiki-platform
XWiki allows unregistered users to access private pages information through REST endpoint
Published
58Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.7epss 0.9%
from disclosure to weapon
Published on NVDMar 19
VulnCheck+169d
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
yesVulnCheck
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
xwiki · xwiki-platformRelated CVEs — xwiki-platform
In the same product, most dangerous first.
CVE-2025-24893CRITICALRemote code execution as guest via SolrSearchMacros request in xwikiEPSS 99.9%KEVCVE-2024-21650CRITICALXWiki Remote Code Execution vulnerability via user registrationEPSS 93.5%CVE-2023-37462CRITICALImproper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-uiEPSS 91.6%CVE-2023-46731CRITICALRemote code execution through the section parameter in Administration as guest in XWiki PlatformEPSS 88.5%CVE-2025-32429CRITICALXWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameterEPSS 87.1%CVE-2023-50719HIGHXWiki Platform Solr search discloses password hashes of all usersEPSS 83.5%
References
https://github.com/xwiki/xwiki-platform/commit/1fb12d2780f37b34a1b4dfdf8457d97ce5cbb2dfhttps://github.com/xwiki/xwiki-platform/commit/bca72f5ce971a31dba2a016d8dd8badda4475206https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-22q5-9phm-744vhttps://jira.xwiki.org/browse/XWIKI-22630https://jira.xwiki.org/browse/XWIKI-22639