CVE-2025-32783

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 30, 2025
CWE ID 668

Summary

CVE-2025-32783 is a vulnerability affecting versions 5.0 to 16.7.1 of XWiki Platform. Users with Message Stream enabled and a wiki configured as closed are at risk. messages sent in a subwiki to "everyone" are actually broadcasted to the entire main wiki, allowing any visitor to view these messages through the Dashboard, even if the subwiki is meant to be private. This issue is not being addressed, as Message Stream has been deprecated in XWiki 16.8.0RC1 and is no longer maintained. A recommended solution is to keep Message Stream disabled by default. Users are advised to disable it through Administration > Social > Message Stream.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share