XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.
2025-03-19T18:15:25.770
2025-05-13T13:34:02.323
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | xwiki | xwiki | < 15.10.15 | Yes |
| Application | xwiki | xwiki | < 16.4.6 | Yes |
| Application | xwiki | xwiki | < 16.10.0 | Yes |
| Application | xwiki | xwiki | 5.4 | Yes |
| Application | xwiki | xwiki | 5.4 | Yes |