CVE-2025-32429
CRITICAL EXPLOITED NUCLEIXWiki Platform - SQL Injection
Title source: nucleiDescription
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.
Exploits (7)
nomisec
WORKING POC
10 stars
by byteReaper77 · infoleak
https://github.com/byteReaper77/CVE-2025-32429
github
WRITEUP
7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-32429.md
Nuclei Templates (1)
XWiki Platform - SQL Injection
CRITICALVERIFIEDby ritikchaddha
Shodan:
html:"data-xwiki-reference"
FOFA:
body="data-xwiki-reference"
References (4)
Scores
CVSS v3
9.8
EPSS
0.2815
EPSS Percentile
96.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-11-03
CWE
CWE-89
Status
published
Products (2)
org.xwiki.platform/xwiki-platform-distribution-war
9.4-rc-1 - 16.10.6Maven
xwiki/xwiki
9.4 - 16.10.6
Published
Jul 24, 2025
Tracked Since
Feb 18, 2026