CVE-2025-65091

CRITICAL

XWiki Full Calendar Macro < 2.4.5 - SQL Injection

Title source: llm
STIX 2.1

Description

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been patched in version 2.4.5.

Scores

CVSS v3 10.0
EPSS 0.0030
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
org.xwiki.contrib/macro-fullcalendar-pom 0 - 2.4.5Maven
xwiki/full_calendar_macro < 2.4.5
Published Jan 10, 2026
Tracked Since Feb 18, 2026