S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 12, 2025

CVE-2025-55749 Scanner

CVE-2025-55749 Scanner - Information Disclosure vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-55749
8.7
CVSShigh
Exploitable remotely over the internet · no authentication required.

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows accessing files which might contains credentials. Fixed in 16.10.11, 17.4.4, and 17.7.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xwiki-platformby xwiki
>= 16.7.0, < 16.10.11
Updated Aug 22, 2026View on NVD →
Detail

XWiki is a popular enterprise wiki software used for creating, managing, and sharing knowledge within an organization. It is often utilized in various sectors including corporate, educational, and non-profit environments. XWiki is designed to facilitate collaboration and improve productivity by providing a platform for information exchange. Its robust set of features includes document management, task workflows, and collaboration tools. Due to its open-source nature, XWiki is highly customizable according to the needs of an organization. Typically, IT departments or administrators manage the deployment and maintenance of XWiki to ensure seamless integration and security.

An information disclosure vulnerability in XWiki allows unauthorized parties to gain access to sensitive information stored within the application. This specific vulnerability arises from exposed contexts that permit static access to files within the webapp directory. By accessing these files, attackers can glean critical information such as configuration settings and potentially sensitive data. Such vulnerabilities pose a significant risk to the confidentiality and integrity of the information managed by XWiki. Mitigating this vulnerability requires updating XWiki to the latest secure version.

The particular information disclosure flaw in XWiki is attributed to the use of the XJetty package, which improperly exposes the context allowing static file access. The vulnerable endpoint in question often involves access points to the `webapps/xwiki/WEB-INF/xwiki.properties` file. Attackers exploiting this vulnerability usually search for specific keywords such as `diff.xml.dataURI` and `core.renderingcache.enabled` in response data to confirm the presence of sensitive information. Properly securing these files is crucial for maintaining the confidentiality of the organization's data. Ensuring the XJetty package has the latest security patches applied is a necessary preventive measure.

Exploitation of the information disclosure vulnerability in XWiki can lead to severe consequences including unauthorized access to sensitive files and credentials. Such access can facilitate further attacks on the system, including privilege escalation or lateral movement within an organization's network. Furthermore, the loss of sensitive data can result in legal liabilities, reputation damage, and financial losses for the affected organization. Addressing this exposure reduces the risk of unauthorized access and secures sensitive organizational data against potential exploitation.

REFERENCES

Solution Advice
  • Update XWiki to version 16.10.11, 17.4.4, or 17.7.0 or later to patch the information disclosure vulnerability.
  • Ensure all server configurations are correctly set to prevent unauthorized file access, especially concerning the XJetty package.
  • Regularly audit and monitor server logs for any suspicious activity that might indicate exploitation attempts.
  • Implement strict access controls and least privilege principles to minimize potential exposure points.
  • Educate and train staff involved in system administration about the latest security best practices and updates related to XWiki.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.