CVE-2025-32969
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-32969 is a vulnerability affecting XWiki, a popular wiki platform. In XWiki versions prior to 15.10.16, 16.4.6, and 16.10.1, an unauthenticated remote user can exploit a SQL injection vulnerability, escaping the HQL execution context. This vulnerability allows attackers to execute arbitrary SQL queries on the backend database, potentially accessing confidential information such as password hashes or altering data through UPDATE/INSERT/DELETE queries. This issue has been addressed in versions 15.10.16, 16.4.6, and 16.10.1. Upgrading XWiki is the recommended mitigation strategy.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.