Reflected XSS Vulnerability in XWiki Platform Affecting Multiple Versions
CVE-2025-32430

6.5MEDIUM

Key Information:

Vendor

Xwiki

Vendor
CVE Published:
6 August 2025

What is CVE-2025-32430?

The XWiki Platform is susceptible to reflected cross-site scripting (XSS) vulnerabilities found in specific templates across several versions. This flaw allows attackers to inject and execute arbitrary JavaScript code when a user visits a malicious URL. As a result, attackers can potentially leverage the victim's session to perform unauthorized actions. Mitigations include upgrading to the patched versions or manually applying the necessary changes to the WAR file.

Affected Version(s)

xwiki-platform >= 4.2-milestone-3, < 16.4.8 < 4.2-milestone-3, 16.4.8

xwiki-platform >= 16.5.0-rc-1, < 16.10.6 < 16.5.0-rc-1, 16.10.6

xwiki-platform >= 17.0.0-rc-1, < 17.3.0-rc-1 < 17.0.0-rc-1, 17.3.0-rc-1

References

CVSS V4

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

.