XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.
History

Tue, 13 May 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki xwiki
Weaknesses CWE-862
CPEs cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:5.4:-:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:5.4:rc1:*:*:*:*:*:*
Vendors & Products Xwiki
Xwiki xwiki
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 19 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 18:00:00 +0000

Type Values Removed Values Added
Description XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.
Title The WikiManager REST API allows any user to create wikis
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 7.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-19T18:21:22.357Z

Reserved: 2025-03-12T13:42:22.136Z

Link: CVE-2025-29926

cve-icon Vulnrichment

Updated: 2025-03-19T18:21:17.810Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-19T18:15:25.770

Modified: 2025-05-13T13:34:02.323

Link: CVE-2025-29926

cve-icon Redhat

No data.