Sensitive Data Exposure in XWiki Platform Product by XWiki
CVE-2025-58049
What is CVE-2025-58049?
In the XWiki Platform, versions ranging from 14.4.2 to prior to 16.4.8, along with specific release candidates, a vulnerability allows sensitive cookies to be stored unencrypted in job statuses during PDF export jobs. This flaw could result in exposure of plaintext passwords if access to system backups is gained. XWiki has implemented patches in later versions to mitigate this issue, ensuring sensitive information is managed securely.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
xwiki-platform >= 14.4.2, < 16.4.8 < 14.4.2, 16.4.8
xwiki-platform >= 16.5.0-rc-1, < 16.10.7 < 16.5.0-rc-1, 16.10.7
xwiki-platform >= 17.0.0-rc-1, < 17.4.0-rc-1 < 17.0.0-rc-1, 17.4.0-rc-1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved