CVE-2025-32429 is a critical SQL injection vulnerability affecting XWiki Platform versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2. This flaw allows unauthenticated attackers to inject SQL commands via the 'sort' parameter in getdeleteddocuments.vm. With a CVSS score of 9.8, it poses a severe risk, enabling full compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, public exploit code exists on ExploitDB and Nuclei templates are available, indicating a high likelihood of exploitation. The vulnerability has garnered significant community discussion, underscoring its importance for immediate patching to versions 16.10.6 or 17.3.0-rc-1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.4, < 16.10.6CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | ||
>= 17.0.0, <= 17.2.2CPE matchmatch criteria | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.