CVE-2025-32969
PoC moderateUnauthenticated Blind SQL Injection in XWiki
XWiki versions from 1.8 up to (but not including) 15.10.16, 16.4.6, and 16.10.1 allow a remote, unauthenticated attacker to escape the HQL execution context and perform a blind SQL injection, executing arbitrary SQL statements against the database backend. The flaw is reachable even when the wiki is configured with "Prevent unregistered users from viewing pages" and "Prevent unregistered users from editing pages" enabled, so guest-accessible instances require no credentials to exploit. Depending on the database backend, the attacker can read confidential data such as password hashes and may run UPDATE, INSERT, and DELETE queries, giving substantial control over the database. All deployments running affected XWiki versions are exposed, and the vendor lists no workaround other than upgrading. Exploitation has not been confirmed in the wild and the issue is not in CISA KEV, but a public advisory exists and EPSS assigns a 77.8% probability of exploitation within 30 days (100th percentile), indicating high near-term risk.
What to do: Upgrade XWiki to 16.10.1, 16.4.6, or 15.10.16 (or any later release), as the advisory lists no application-level workaround. Until patched, limit network access to the instance and review database logs for unexpected SQL activity or read/write access to password hash tables. Treat internet-facing instances that allow unauthenticated access as the highest priority for patching.
| xwiki | all versions >= 1.8 and < 15.10.16; >= 15.10.16 and < 16.4.6; >= 16.4.6 and < 16.10.1 (fixed in 15.10.16, 16.4.6, and 16.10.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database backend, including when "Prevent unregistered users from viewing pages, regardless of the page rights" and "Prevent unregistered users from editing pages, regardless of the page rights" options are enabled. Depending on the used database backend, the attacker may be able to not only obtain confidential information such as password hashes from the database, but also execute UPDATE/INSERT/DELETE queries. This issue has been patched in versions 16.10.1, 16.4.6 and 15.10.16. There is no known workaround, other than upgrading XWiki.
- Vendors
- xwiki
- Products
- xwiki
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.