Vulnerability in XWiki Platform Allows Unauthorized Message Access
CVE-2025-32783
4.3MEDIUM
What is CVE-2025-32783?
A security flaw in the XWiki Platform affects versions 5.0 to 16.7.1, specifically impacting users with the Message Stream feature enabled. When a subwiki is configured as closed and the option 'Prevent unregistered users from viewing pages' is selected, messages intended for 'everyone' in the subwiki are exposed to the main wiki's visitors. This means unauthorized users can view these messages via the Dashboard, compromising the privacy of the closed subwiki. As the Message Stream feature has been deprecated in version 16.8.0RC1, no patch will be issued. Users are advised to disable the Message Stream by default in the Administration settings under Social.
Affected Version(s)
xwiki-platform >= 5.0, <= 16.7.1