S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 19, 2025

CVE-2025-55748 Scanner

CVE-2025-55748 Scanner - Path Traversal vulnerability in XWiki Platform

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-55748
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false`. This is fixed in version 16.10.7.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xwiki-platformby xwiki
>= 4.2-milestone-2, < 16.10.7
Updated Aug 22, 2026View on NVD →
Detail

XWiki Platform is a powerful and adaptable open-source application built around a second-generation wiki, primarily used for collaborative content creation and management. It caters to organizations, enterprises, and educational institutions, providing features such as knowledge management, documentation, and collaboration tools. The platform supports extensibility through plugins and customization, allowing tailored functionalities to suit specific user needs. Additionally, XWiki is commonly deployed in environments requiring structured content organization, such as corporate intranets and project management systems. Due to its versatility, it is widely adopted in both private and public sectors to foster efficient communication and information sharing.

This path traversal vulnerability in the XWiki Platform arises from improper access control in the jsx and sx endpoints. It allows unauthorized remote attackers to read sensitive configuration files, potentially leading to further compromise of the affected system. This vulnerability requires no special privileges to exploit, making it particularly concerning for administrators of XWiki instances. It occurs due to the lack of validation and sanitization of user input in critical endpoints, enabling malicious users to traverse directories and access restricted locations. Addressing this flaw is crucial to safeguard the confidentiality of system configurations and prevent potential exploitation.

The vulnerability technically stems from inadequate controls over filename paths, permitting directory traversal attacks. Specifically, the vunerable endpoints such as /bin/ssx/Main/WebHome can be queried with crafted inputs like '../' sequences to breach directory boundaries. In this exploit, attackers can insert sequences to bypass restrictions and reach sensitive files within the system, such as configuration files located in directories like WEB-INF. Upon successful execution, attackers can view and extract contents like configuration settings, posing a risk to the broader security posture of the application.

When exploited, this path traversal vulnerability can compromise sensitive data, including configuration parameters of the XWiki Platform. The exposure of such configurations can lead to unauthorized access to secured areas, allowing attackers to discover and exploit additional vulnerabilities. Leakage of system internals could facilitate further attacks, such as privilege escalation or data exfiltration. Consequently, this vulnerability can undermine the confidentiality and integrity of the system, and immediate action is required to mitigate the risk.

REFERENCES

Solution Advice
  • Upgrade XWiki Platform to version 16.10.7 or later to patch this vulnerability.
  • Ensure that proper input validation and sanitation are implemented in all user-accessible endpoints.
  • Regularly review and update access control configurations to prevent unauthorized file access.
  • Monitor application logs for suspicious activities indicating potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.