{"id":"CVE-2025-55748","title":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it","summary":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to acces…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-23"],"vendor":"xwiki","product":"xwiki","affected":["xwiki >= 4.3, < 16.10.7","xwiki >= 17.0.0, <= 17.3.0","xwiki = 4.2"],"patched":["xwiki 16.10.7"],"published":"2025-09-03","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-55748","references":[{"url":"https://github.com/xwiki/xwiki-platform/commit/9e7b4c03f2143978d891109a17159f73d4cdd318#diff-ee78930a9ac5ea586179fe8ab88a5fd58e369d175927d1e88a0b4dbc3ebcbf1eR62","label":"security-advisories@github.com"},{"url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-m63c-3rmg-r2cf","label":"security-advisories@github.com"},{"url":"https://jira.xwiki.org/browse/XWIKI-23109","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.01771,"epssPercentile":0.77301,"exploits":{"nuclei":["CVE-2025-55748"],"checkedAt":"2026-09-30T23:30:07.494Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T23:29:32.357Z","slug":"CVE-2025-55748","body":"## Overview\n\nXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false`. This is fixed in version 16.10.7.\n\n## Affected\n\n- `xwiki >= 4.3, < 16.10.7`\n- `xwiki >= 17.0.0, <= 17.3.0`\n- `xwiki = 4.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `xwiki 16.10.7`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[]}