CVE-2025-55748High· 7.5▾ MidnightPoC availableXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to acces…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
Nuclei ×1 (last check)
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false. This is fixed in version 16.10.7.
xwiki >= 4.3, < 16.10.7xwiki >= 17.0.0, <= 17.3.0xwiki = 4.2Upgrade past the affected range:
xwiki 16.10.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-55749High· 7.5XWiki is an open-source wiki software platform
CVE-2025-66472Medium· 6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2026-33229Critical· 9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2025-58049Medium· 5.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2025-66473High· 7.5XWiki is an open-source wiki software platform
CVE-2025-66024Critical· 9.0The XWiki blog application allows users of the XWiki platform to create and manage blog posts