Information Disclosure in XWiki Platform Versions
CVE-2025-49584

8.7HIGH

Key Information:

Vendor

Xwiki

Vendor
CVE Published:
13 June 2025

What is CVE-2025-49584?

In certain versions of the XWiki Platform, an information disclosure vulnerability exists that allows attackers to access the titles of wiki pages through the REST API if an XClass with a page property is available. This exposure is possible for any known page reference, enabling one title retrieval per request. While the risk to confidentiality is primarily low for default installations—where page names typically align with titles—obfuscation of page names could elevate risk levels if titles contain sensitive information. This security flaw has been addressed in versions 16.4.7, 16.10.3, and 17.0.0, which introduced additional access control checks for title retrieval.

Affected Version(s)

xwiki-platform >= 10.9, < 16.4.7 < 10.9, 16.4.7

xwiki-platform >= 16.5.0-rc-1, < 16.10.3 < 16.5.0-rc-1, 16.10.3

xwiki-platform >= 17.0.0-rc-1, < 17.0.0 < 17.0.0-rc-1, 17.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.