Skip to main content
CRITICAL

CVE-2025-29926

CVSS v3

9.8

CRITICAL

EPSS Score

1.5 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.

Technical details

Published
2025-03-19

Frequently asked questions

What is CVE-2025-29926?

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.

Is CVE-2025-29926 actively exploited?

Active exploitation of CVE-2025-29926 has not been confirmed. The EPSS score is 1.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-29926?

CVE-2025-29926 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2025-29926 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key