CVE-2025-54124 Details
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with editing rights can create an XClass with a database list property that references a password property. When adding an object of that XClass, the content of that password property is displayed. In practice, with a standard rights setup, this means that any user with an account on the wiki can access password hashes of all users, and possibly other password properties (with hashed or plain storage) that are on pages that the user can view. This issue is fixed in versions 16.4.7, 16.10.5 and 17.2.0-rc-1.
A vulnerability exists in XWiki Platform Legacy Old Core and Old Core versions 9.8-rc-1 prior to 16.4.7, 16.5.0-rc-1 prior to 16.10.5, and 17.0.0-rc-1 prior to 17.2.0-rc-1. Any user with editing rights can create an XClass that includes a database list property referencing a password property. When an object of this XClass is added, the password property's content is revealed. This allows users to access password hashes of all users, and potentially other password properties stored as plain text or hashes, from pages they can view.
Users can update to XWiki versions 16.4.7, 16.10.5, or 17.2.0-rc-1, where this vulnerability has been fixed by disallowing the use of password properties in database list properties. Queries for email properties are also restricted when email obfuscation is enabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jira.xwiki.org/browse/XWIKI-22811 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/f2ca8649cba2ed3765061660bf5c7f801afa0b24 | [email protected] | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-r38m-cgpg-qj69 | [email protected] | Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-22811 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xwiki xwiki | >= 9.8, < 16.4.7 >= 16.5.0, < 16.10.5 >= 17.0.0, <= 17.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2025 | Initial Analysis | [email protected] |
| Aug 6, 2025 | CVE Modified | CISA-ADP |
| Aug 6, 2025 | New CVE Received | [email protected] |