CVE-2025-29926

Source
https://cve.org/CVERecord?id=CVE-2025-29926
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29926.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-29926
Aliases
Published
2025-03-19T17:40:44.937Z
Modified
2026-07-15T02:14:19.130966994Z
Severity
  • 7.9 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H CVSS Calculator
Summary
The WikiManager REST API allows any user to create wikis
Details

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-285"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29926.json"
}
References

Affected packages

Git / github.com/xwiki/xwiki-commons

Affected ranges

Type
GIT
Repo
https://github.com/xwiki/xwiki-commons
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:xwiki:xwiki:5.4:-:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "5.4.1"
        },
        {
            "fixed": "15.10.15"
        },
        {
            "introduced": "16.0.0"
        },
        {
            "fixed": "16.4.6"
        },
        {
            "introduced": "16.5.0"
        },
        {
            "fixed": "16.10.0"
        },
        {
            "introduced": "5.4-NA"
        },
        {
            "last_affected": "5.4-NA"
        }
    ]
}
Type
GIT
Repo
https://github.com/xwiki/xwiki-platform
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": [
        "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:xwiki:xwiki:5.4:-:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "5.4.1"
        },
        {
            "fixed": "15.10.15"
        },
        {
            "introduced": "16.0.0"
        },
        {
            "fixed": "16.4.6"
        },
        {
            "introduced": "16.5.0"
        },
        {
            "fixed": "16.10.0"
        },
        {
            "introduced": "5.4-NA"
        },
        {
            "last_affected": "5.4-NA"
        }
    ]
}

Affected versions

5.*
5.4-NA
xwiki-commons-5.*
xwiki-commons-5.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29926.json"