CVE-2025-65091

CRITICAL

Xwiki Full Calendar Macro < 2.4.5 - SQL Injection

Title source: rule

Description

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been patched in version 2.4.5.

Scores

CVSS v3 10.0
EPSS 0.0020
EPSS Percentile 41.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-89
Status published

Affected Products (2)

xwiki/full_calendar_macro < 2.4.5
org.xwiki.contrib/macro-fullcalendar-pom < 2.4.5Maven

Timeline

Published Jan 10, 2026
Tracked Since Feb 18, 2026