S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 16, 2026

CVE-2025-66472 Scanner

CVE-2025-66472 Scanner - Cross-Site Scripting vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-66472
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates are vulnerable to a reflected XSS attack through a deletion confirmation message. The attacker-supplied script is executed when the victim clicks the "No" button. This issue is fixed in versions 16.10.10 and 17.4.2 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates.

Attack Vector
Network
Privileges Req.
None
User Interaction
P
Affected
xwiki-platformby xwiki
org.xwiki.platform:xwiki-platform-flamingo-skin-resources >= 6.2-milestone-1, < 16.10.10
Updated Aug 22, 2026View on NVD →
Detail

XWiki is a widely-used generic wiki platform providing runtime services for applications. It is utilized by developers globally to create and support both collaborative and standalone applications within a wiki environment. XWiki is often deployed in enterprise environments where collaboration and documentation are key. The platform allows users to build applications on top of it, offering an extensible and flexible environment. It often features in knowledge management and content management systems where ease of use and collaborative capabilities are desired. Users and developers leverage its features to strengthen community engagement through editable, user-generated content.

A Cross-Site Scripting (XSS) vulnerability in XWiki can lead to significant security risks for users. XSS allows attackers to inject scripts into web pages viewed by other users. These vulnerabilities expose an application to potential malicious actions, such as session hijacking, data theft, and similar exploits. In the context of XWiki, such a vulnerability arises from improper coding practices that do not sanitize or encode user-input adequately. As a widely adopted platform, XWiki's vulnerability to XSS could impact numerous installations. Addressing these vulnerabilities is critical to maintaining the integrity and security of content.

The specific XSS vulnerability identified in CVE-2025-66472 affects the deletion confirmation message in XWiki, triggered when a user clicks the "No" button. This particular vulnerability allows for a reflected XSS attack by executing an attacker-supplied script. The attack takes advantage of the URL structures involving the "appName" and "xredirect" parameters. These endpoints do not adequately neutralize script-related content embedded within, leading to exposure to malicious scripts. Attackers can manipulate URLs in ways that invite victims to load the generated script unintentionally, leading to broader compromise.

The exploitation of a Cross-Site Scripting (XSS) vulnerability in XWiki can cause severe ramifications. Users are at risk of session hijacking, potentially allowing attackers to impersonate them in applications. Additionally, attackers might steal sensitive data such as login credentials or private user information stored within the wiki. Further exploitation could lead to distribution of malware or the redirection of users to malicious websites. Organizations using vulnerable versions of XWiki could encounter these serious consequences, impacting their confidentiality, integrity, and availability.

REFERENCES

Solution Advice
  • Upgrade to XWiki version 16.10.10 or 17.4.2 or above to mitigate the vulnerability.
  • Regularly update and patch XWiki installations to address newly discovered vulnerabilities.
  • Implement input sanitization mechanisms to prevent XSS attacks.
  • Conduct regular security audits and employ tools to detect XSS vulnerabilities.
  • Educate users on the risks of interacting with suspicious links and instruct them on safe browsing practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.