CVE-2025-49586

XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:7.2:milestone2:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:7.2:milestone3:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:17.0.0:rc1:*:*:*:*:*:*

History

03 Sep 2025, 17:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:xwiki:xwiki:7.2:milestone2:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:7.2:milestone3:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:17.0.0:rc1:*:*:*:*:*:*
References () https://github.com/xwiki/xwiki-platform/commit/ef978315649cf83eae396021bb33603a1a5f7e42 - () https://github.com/xwiki/xwiki-platform/commit/ef978315649cf83eae396021bb33603a1a5f7e42 - Patch
References () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jp4x-w9cj-97q7 - () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jp4x-w9cj-97q7 - Vendor Advisory
References () https://jira.xwiki.org/browse/XWIKI-22719 - () https://jira.xwiki.org/browse/XWIKI-22719 - Exploit, Issue Tracking, Vendor Advisory
First Time Xwiki
Xwiki xwiki

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) XWiki es una plataforma de software wiki de código abierto. Cualquier usuario de XWiki con permisos de edición en al menos una aplicación de App Within Minutes (el permiso predeterminado para todos los usuarios de XWiki) puede obtener permisos de programación y ejecutar código remoto editando la aplicación. Esta vulnerabilidad se ha corregido en XWiki 17.0.0, 16.4.7 y 16.10.3.

13 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 18:15

Updated : 2025-09-03 17:47


NVD link : CVE-2025-49586

Mitre link : CVE-2025-49586

CVE.ORG link : CVE-2025-49586


JSON object : View

Products Affected

xwiki

  • xwiki
CWE
CWE-863

Incorrect Authorization