CVE-2025-65091

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-65091
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65091.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-65091
Aliases
Published
2026-01-10T03:06:16.775Z
Modified
2026-01-12T19:42:27.610836Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService
Details

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been patched in version 2.4.5.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65091.json"
}
References

Affected packages

Git / github.com/xwiki-contrib/macro-fullcalendar

Affected ranges

Type
GIT
Repo
https://github.com/xwiki-contrib/macro-fullcalendar
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

macro-fullcalendar-1.*

macro-fullcalendar-1.1.6
macro-fullcalendar-1.1.7
macro-fullcalendar-1.1.8
macro-fullcalendar-1.1.9

macro-fullcalendar-2.*

macro-fullcalendar-2.0
macro-fullcalendar-2.0.1
macro-fullcalendar-2.0.2
macro-fullcalendar-2.0.3
macro-fullcalendar-2.0.4
macro-fullcalendar-2.1
macro-fullcalendar-2.2.1
macro-fullcalendar-2.2.10
macro-fullcalendar-2.2.11
macro-fullcalendar-2.2.2
macro-fullcalendar-2.2.3
macro-fullcalendar-2.2.5
macro-fullcalendar-2.2.6

macro-fullcalendar-pom-2.*

macro-fullcalendar-pom-2.1.1
macro-fullcalendar-pom-2.1.2
macro-fullcalendar-pom-2.1.3
macro-fullcalendar-pom-2.1.4
macro-fullcalendar-pom-2.1.5
macro-fullcalendar-pom-2.1.6
macro-fullcalendar-pom-2.1.7
macro-fullcalendar-pom-2.1.8
macro-fullcalendar-pom-2.1.9
macro-fullcalendar-pom-2.2
macro-fullcalendar-pom-2.2.12
macro-fullcalendar-pom-2.2.4
macro-fullcalendar-pom-2.2.7
macro-fullcalendar-pom-2.2.8
macro-fullcalendar-pom-2.2.9
macro-fullcalendar-pom-2.3.0
macro-fullcalendar-pom-2.3.1
macro-fullcalendar-pom-2.3.2
macro-fullcalendar-pom-2.4.0
macro-fullcalendar-pom-2.4.1
macro-fullcalendar-pom-2.4.2
macro-fullcalendar-pom-2.4.3
macro-fullcalendar-pom-2.4.4

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65091.json"