CVE-2025-32974 Details
Description
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since version 15.9 when there is content on the page like a script macro that would gain more rights due to the editing. This analysis doesn't consider certain kinds of properties, allowing a user to put malicious scripts in there that will be executed after a user with script, admin, or programming rights edited the page. Such a malicious script could impact the confidentiality, integrity and availability of the whole XWiki installation. This issue has been patched in versions 15.10.8 and 16.2.0.
A vulnerability exists in XWiki versions 15.9-rc-1 prior to 15.10.8 and 16.0.0-rc-1 prior to 16.2.0. The issue arises because the rights analysis for TextAreas with the default content type does not properly account for certain properties. This oversight allows users to inject malicious scripts that could be executed by users with script, admin, or programming rights, potentially compromising the entire XWiki installation.
Users can update to XWiki versions 15.10.8 or 16.2.0, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jira.xwiki.org/browse/XWIKI-22002 | CISA-ADP | Issue TrackingVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/153dbfa2ef1a7a0a644fe3f889684c6a8738c5fc | [email protected] | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-mvgm-3rw2-7j4r | [email protected] | PatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-22002 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xwiki xwiki | >= 15.9, < 15.10.8 >= 16.0.0, < 16.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2025 | Initial Analysis | [email protected] |
| Apr 30, 2025 | CVE Modified | CISA-ADP |
| Apr 30, 2025 | New CVE Received | [email protected] |