XWiki Wiki Platform Vulnerability in Script API Affects Cache Management
CVE-2025-32972

2.7LOW

Key Information:

Vendor
Xwiki
Vendor
CVE Published:
30 April 2025

Summary

In the XWiki platform, a vulnerability in the script API of the LESS compiler allows users to call the cache cleaning function without the requisite programming rights. This flaw is present from XWiki versions 6.1-milestone-1 to just before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to just before 16.8.0-rc-1. Although it permits cache cleaning, the primary consequence is a performance degradation due to cache refilling. The vulnerability requires script rights for exploitation, which already provides significant control over the execution of scripts. This issue has been resolved in updates 15.10.12, 16.4.3, and 16.8.0-rc-1.

Affected Version(s)

xwiki-platform >= 6.1-milestone-1, < 15.10.12 < 6.1-milestone-1, 15.10.12

xwiki-platform >= 16.0.0-rc-1, < 16.4.3 < 16.0.0-rc-1, 16.4.3

xwiki-platform >= 16.5.0-rc-1, < 16.8.0-rc-1 < 16.5.0-rc-1, 16.8.0-rc-1

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.