XWiki Vulnerability Allows Unauthorized Script Execution Due to Link Mismanagement
CVE-2025-49580
What is CVE-2025-49580?
A vulnerability has been identified in XWiki where a page can gain script or programming rights when the target of a link is renamed or moved. This allows for the potential execution of scripts that should not have been authorized in the first place. Versions from 8.2 and 7.4.5 up to 17.1.0-rc-1, 16.10.4, and 16.4.7 are at risk. The issue has been resolved in later releases, ensuring better security against unauthorized script execution. For further details, you can refer to the security advisories and commit documentation that outline the specific changes made.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
xwiki-platform >= 17.0.0-rc-1, < 17.1.0-rc-1 < 17.0.0-rc-1, 17.1.0-rc-1
xwiki-platform >= 16.5.0-rc-1, < 16.10.4 < 16.5.0-rc-1, 16.10.4
xwiki-platform >= 8.2, < 16.4.7 < 8.2, 16.4.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved