XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27604.json",
"cwe_ids": [
"CWE-200"
],
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:xwiki:confluence_migrator:*:*:*:*:pro:xwiki:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.11.7"
}
]
}
[
{
"id": "CVE-2025-27604-a4a056f2",
"target": {
"file": "application-confluence-migrator-pro-default/src/main/java/com/xwiki/confluencepro/internal/DefaultConfluenceMigrationManager.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"237082852979082871744884121558411992024",
"318073809440962781221748666385396254512",
"3714454333198568705618567396363090802",
"285837633087357529119334618879287836177",
"212229344452513366728537249169254307539",
"299713605154950890762739111154944087549",
"94912573224414276312866846987584484218",
"314963479118972017902773246500422778418",
"269187174114217737333992952965945749271",
"63027522671517888980567883281421047007",
"86021175863316733950052000403315122891",
"288631320325930466339612697656433052139",
"67423162539767398779433642600389177653",
"115137378768262563546338609886525507418",
"241542396635549088895830750341006497366",
"215429603811608496821921065378764772255",
"330385544053692898254614182688465175929",
"164938992340548661030266079008873119186",
"106135331788522210809063399029977357170",
"245810853880998209973227079252545382593",
"337802565898630179438665926021631139687",
"163740532226727614003420187198520982704",
"298460804947853540236576844984236433678",
"79836929593607415769750065292812856484",
"204871176720001208015842811556722702122",
"153411268766052645545275359010488785279",
"95957088946061686362509929086601384440",
"300723281369245910830064821162425312017",
"150018515627237589353381515692306664443",
"289300569083683388698951904928086649747",
"85523093135311577351928599651641992801",
"71454865619359326485443025832369478940",
"322929944945235996911447305629119659837",
"78254233181598117589519984853362929064",
"325145382035865138146571296787208834480",
"18453726156929124966942755471965172146",
"305140215436331914223442264265929057052",
"94864178984946326703800467699247193418",
"107090622202024400508243772725358266169"
]
},
"signature_version": "v1",
"source": "https://github.com/xwikisas/application-confluence-migrator-pro/commit/6ced42b1f341fd0ce6734fc58c7d694da5f365fb",
"signature_type": "Line"
},
{
"id": "CVE-2025-27604-d1002745",
"target": {
"function": "persistMacroMap",
"file": "application-confluence-migrator-pro-default/src/main/java/com/xwiki/confluencepro/internal/DefaultConfluenceMigrationManager.java"
},
"deprecated": false,
"digest": {
"function_hash": "185685520931605541314798376455282473504",
"length": 2056.0
},
"signature_version": "v1",
"source": "https://github.com/xwikisas/application-confluence-migrator-pro/commit/6ced42b1f341fd0ce6734fc58c7d694da5f365fb",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27604.json"
"2026-08-12T15:16:22Z"