CVE-2025-52133: XWiki-Contrib Mocca Calendar
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.
Affected products
- XWiki-Contrib Mocca Calendar: before 2.15 (fixed in 2.15)
Published 2025-08-03. Last modified 2026-06-17.