XWiki Wiki Platform Vulnerability in Script API Affects Cache Management
CVE-2025-32972
Summary
In the XWiki platform, a vulnerability in the script API of the LESS compiler allows users to call the cache cleaning function without the requisite programming rights. This flaw is present from XWiki versions 6.1-milestone-1 to just before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to just before 16.8.0-rc-1. Although it permits cache cleaning, the primary consequence is a performance degradation due to cache refilling. The vulnerability requires script rights for exploitation, which already provides significant control over the execution of scripts. This issue has been resolved in updates 15.10.12, 16.4.3, and 16.8.0-rc-1.
Affected Version(s)
xwiki-platform >= 6.1-milestone-1, < 15.10.12 < 6.1-milestone-1, 15.10.12
xwiki-platform >= 16.0.0-rc-1, < 16.4.3 < 16.0.0-rc-1, 16.4.3
xwiki-platform >= 16.5.0-rc-1, < 16.8.0-rc-1 < 16.5.0-rc-1, 16.8.0-rc-1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved