CVE-2025-66473High· 7.5▾ TwilightXWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single request at the moment. Depending on the number of pages in the wiki and the memory configuration, this can lead to slowness and unavailability of the wiki. As an example, the /rest/wikis/xwiki/spaces resource returns all spaces on the wiki by default, which are basically all pages. This issue is fixed in versions 17.4.4 and 16.10.11.
xwiki < 16.10.11xwiki >= 17.0.0, < 17.4.4xwiki >= 17.5.0, <= 17.6.0Upgrade past the affected range:
xwiki 17.4.4Connected by shared product, vendor, weakness, or advisory.
CVE-2025-55749High· 7.5XWiki is an open-source wiki software platform
CVE-2025-58049Medium· 5.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2025-66472Medium· 6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2026-33229Critical· 9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak
CVE-2025-11362High· 7.5Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding