CVE-2025-32429

CRITICAL EXPLOITED NUCLEI

XWiki Platform - SQL Injection

Title source: nuclei

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

Exploits (7)

exploitdb WORKING POC
by Byte Reaper · cwebappsmultiple
https://www.exploit-db.com/exploits/52384
nomisec WORKING POC 10 stars
by byteReaper77 · infoleak
https://github.com/byteReaper77/CVE-2025-32429
github WRITEUP 7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-32429.md
nomisec WORKING POC
by TheNaderr · poc
https://github.com/TheNaderr/CVE-2025-32429
nomisec SCANNER
by imbas007 · poc
https://github.com/imbas007/CVE-2025-32429-Checker
nomisec WORKING POC
by amir-othman · infoleak
https://github.com/amir-othman/CVE-2025-32429
vulncheck_xdb SCANNER
infoleak
https://github.com/imbas007/CVE-2025-32429-Checker-

Nuclei Templates (1)

XWiki Platform - SQL Injection
CRITICALVERIFIEDby ritikchaddha
Shodan: html:"data-xwiki-reference"
FOFA: body="data-xwiki-reference"

Scores

CVSS v3 9.8
EPSS 0.2815
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-11-03
CWE
CWE-89
Status published
Products (2)
org.xwiki.platform/xwiki-platform-distribution-war 9.4-rc-1 - 16.10.6Maven
xwiki/xwiki 9.4 - 16.10.6
Published Jul 24, 2025
Tracked Since Feb 18, 2026