CVE-2025-32969

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 30, 2025
CWE ID 89

Summary

CVE-2025-32969 is a vulnerability affecting XWiki, a popular wiki platform. In XWiki versions prior to 15.10.16, 16.4.6, and 16.10.1, an unauthenticated remote user can exploit a SQL injection vulnerability, escaping the HQL execution context. This vulnerability allows attackers to execute arbitrary SQL queries on the backend database, potentially accessing confidential information such as password hashes or altering data through UPDATE/INSERT/DELETE queries. This issue has been addressed in versions 15.10.16, 16.4.6, and 16.10.1. Upgrading XWiki is the recommended mitigation strategy.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share