Configuration File Exposure Vulnerability in XWiki Platform by XWiki
CVE-2025-55747

9.3CRITICAL

Key Information:

Vendor

Xwiki

Vendor
CVE Published:
3 September 2025

What is CVE-2025-55747?

The XWiki Platform version 6.1-milestone-2 through 16.10.6 contains a vulnerability that allows unauthorized access to sensitive configuration files via the webjars API. This exposure could potentially lead to the disclosure of sensitive information, including authentication credentials and system configurations, posing a significant security risk for applications built on the platform. The issue has been addressed in version 16.10.7, which is recommended for all users to mitigate this vulnerability.

Affected Version(s)

xwiki-platform >= 6.1-milestone-2, < 16.10.7

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55747 : Configuration File Exposure Vulnerability in XWiki Platform by XWiki