CVE-2025-49585 - CVE House
Back to Database
Status published High CVE-2025-49585

XWiki does not require right warnings for XClass definitions

Vulnerability Description

XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that same document is later edited by a user with script, admin, or programming right, malicious code could be executed with the rights of the editing user without prior warning. In particular, this concerns custom display code, the script of computed properties and queries in database list properties. Note that warnings before editing documents with dangerous properties have only been introduced in XWiki 15.9, before that version, this was a known issue and the advice was simply to be careful. This has been patched in XWiki 16.10.2, 16.4.7 and 15.10.16 by adding an analysis for the respective XClass properties.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49585

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

xwiki-platform
Vulnerable Versions:
< 15.10.16, >= 16.0.0-rc-1, < 16.4.7, >= 16.5.0-rc-1, < 16.10.2

Timeline

Official Publish: June 13th, 2025
Last Modified: June 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.