CVE-2025-58049Medium· 5.8▾ SunlitXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1.
xwiki >= 14.4.2, < 16.4.8xwiki >= 16.5.0, < 16.10.7xwiki >= 17.0.0, <= 17.3.0Upgrade past the affected range:
xwiki 16.10.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-55749High· 7.5XWiki is an open-source wiki software platform
CVE-2025-66473High· 7.5XWiki is an open-source wiki software platform
CVE-2025-66472Medium· 6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2026-33229Critical· 9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2025-66474High· 8.8XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)
CVE-2025-65036High· 8.3XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence