CVE-2025-29925 is a medium-severity information disclosure vulnerability affecting XWiki Platform versions prior to 15.10.14, 16.4.6, and 16.10.0-rc-1. It allows unauthenticated attackers to list protected pages via the REST API, even if view rights are restricted, potentially exposing sensitive page titles. The CVSS score is 5.3 (Medium), indicating low attack complexity and no user interaction required, with a limited impact on confidentiality. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detecting this vulnerability, and community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.9, < 15.10.14CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 16.0.0, < 16.4.6CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 16.5.0, <= 16.10.0CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.