CVE-2025-32783
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-32783 is a vulnerability affecting versions 5.0 to 16.7.1 of XWiki Platform. Users with Message Stream enabled and a wiki configured as closed are at risk. messages sent in a subwiki to "everyone" are actually broadcasted to the entire main wiki, allowing any visitor to view these messages through the Dashboard, even if the subwiki is meant to be private. This issue is not being addressed, as Message Stream has been deprecated in XWiki 16.8.0RC1 and is no longer maintained. A recommended solution is to keep Message Stream disabled by default. Users are advised to disable it through Administration > Social > Message Stream.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xwiki
Affected Vendors
- xwiki