CVE-2025-29926: XWiki
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.
Affected products
- XWiki XWiki: from 5.4.1, before 15.10.15 (fixed in 15.10.15); from 16.0.0, before 16.4.6 (fixed in 16.4.6); from 16.5.0, before 16.10.0 (fixed in 16.10.0); version 5.4 only
Published 2025-03-19. Last modified 2026-06-17.