CVE-2025-55747: XWiki
Critical severity, CVSS 9.1. EPSS: 1.7% chance of exploitation in the next 30 days.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.10.7.
Affected products
- XWiki XWiki: from 6.2, before 16.10.7 (fixed in 16.10.7); from 17.0.0, up to and including 17.3.0; version 6.1 only
Published 2025-09-03. Last modified 2026-06-17.