CVE-2025-49580

HIGH

Xwiki < 16.4.7 - Incorrect Privilege Assignment

Title source: rule
STIX 2.1

Description

XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts contained in xobjects that should have never been executed. This vulnerability is fixed in 17.1.0-rc-1, 16.10.4, and 16.4.7.

References (3)

Core 3

Scores

CVSS v3 8.0
EPSS 0.0080
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (2)
org.xwiki.platform/xwiki-platform-refactoring-default 17.0.0-rc-1 - 17.1.0-rc-1Maven
xwiki/xwiki 7.4.5 - 16.4.7
Published Jun 13, 2025
Tracked Since Feb 18, 2026