SQL Injection Vulnerability in XWiki Platform by XWiki
CVE-2025-32429

9.3CRITICAL

Key Information:

Vendor

Xwiki

Vendor
CVE Published:
24 July 2025

What is CVE-2025-32429?

An SQL injection vulnerability exists in the XWiki Platform, specifically in the handling of the 'sort' parameter within the getdeleteddocuments.vm file. This flaw allows an attacker to inject arbitrary SQL code, which could lead to unauthorized data access and manipulation. It affects versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2 but is mitigated in versions 16.10.6 and 17.3.0-rc-1. Users are encouraged to upgrade to these revised versions to safeguard against potential exploits.

Affected Version(s)

xwiki-platform >= 9.4-rc-1, < 16.10.6 < 9.4-rc-1, 16.10.6

xwiki-platform >= 17.0.0-rc-1, < 17.3.0-rc-1 < 17.0.0-rc-1, 17.3.0-rc-1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32429 : SQL Injection Vulnerability in XWiki Platform by XWiki