XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Jul 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xwiki
Xwiki xwiki-platform |
|
Vendors & Products |
Xwiki
Xwiki xwiki-platform |
Fri, 25 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Jul 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1. | |
Title | XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-24T22:22:35.102Z
Updated: 2025-07-25T13:32:47.835Z
Reserved: 2025-04-08T10:54:58.367Z
Link: CVE-2025-32429

Updated: 2025-07-25T13:32:40.312Z

Status : Awaiting Analysis
Published: 2025-07-24T23:15:26.283
Modified: 2025-07-25T15:29:19.837
Link: CVE-2025-32429

No data.