Information Disclosure in XWiki Platform Versions
CVE-2025-49584
What is CVE-2025-49584?
In certain versions of the XWiki Platform, an information disclosure vulnerability exists that allows attackers to access the titles of wiki pages through the REST API if an XClass with a page property is available. This exposure is possible for any known page reference, enabling one title retrieval per request. While the risk to confidentiality is primarily low for default installations—where page names typically align with titles—obfuscation of page names could elevate risk levels if titles contain sensitive information. This security flaw has been addressed in versions 16.4.7, 16.10.3, and 17.0.0, which introduced additional access control checks for title retrieval.
Affected Version(s)
xwiki-platform >= 10.9, < 16.4.7 < 10.9, 16.4.7
xwiki-platform >= 16.5.0-rc-1, < 16.10.3 < 16.5.0-rc-1, 16.10.3
xwiki-platform >= 17.0.0-rc-1, < 17.0.0 < 17.0.0-rc-1, 17.0.0