S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 29, 2025

CVE-2025-46554 Scanner

CVE-2025-46554 Scanner - Information Disclosure vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-46554
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the wiki using the wiki attachment REST endpoint. There is no filtering for the results depending on current user rights, meaning an unauthenticated user could exploit this even in a private wiki. This issue has been patched in versions 14.10.22, 15.10.12, 16.4.3, and 16.7.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xwiki-platformby xwiki
>= 1.8.1, < 14.10.22
Updated Aug 22, 2026View on NVD →
Detail

XWiki is an enterprise wiki application written in Java, used by software development teams, enterprises, and other collaborative environments for documentation and knowledge sharing. It provides a robust platform for creating, sharing, and managing documents and knowledge bases. Organizations use XWiki to centralize their documentation efforts, streamline communication, and foster collaboration within teams across different departments. The software allows for extensive customization and integration, which makes it highly adaptable to different organizational needs. Common users include project managers, developers, and documentation specialists who require efficient document tracking and versioning. The platform's open-source nature contributes to its widespread adoption and continuous improvement by a community of contributors.

An Information Disclosure vulnerability in XWiki's REST API exposes attachment metadata to unauthorized users. This vulnerability occurs when unauthenticated users can access the attachments list and metadata via the API, leading to potential exposure of sensitive information. The flaw arises due to insufficient access controls on the attachments endpoint, allowing unauthorized viewing of attachment details. This kind of vulnerability can lead to a breach of confidential information, potentially affecting organizational security and privacy. Organizations using XWiki must recognize the importance of securing their REST API endpoints to prevent unauthorized access to sensitive data. Ensuring proper authentication checks can mitigate the risks associated with this vulnerability.

The vulnerability is found within the XWiki REST API, specifically affecting the endpoint that handles attachments. Unauthorized users can exploit this by sending a GET request to the vulnerable endpoint, thereby accessing attachment metadata without proper authentication. The endpoint allows access to `

If exploited, this vulnerability could lead to significant breaches of data confidentiality, as attackers could gain access to potentially sensitive attachments metadata from the XWiki database. Organizations may suffer from unauthorized access to confidential documents and files, potentially leading to data leaks. This could further result in loss of intellectual property, damage to organizational reputation, and financial loss. Users might face data privacy violations, and the organization may incur fines and compliance issues, depending on the nature of the exposed information. It emphasizes the need for regular security audits and updates to prevent such vulnerabilities from compromising sensitive organizational data.

REFERENCES

Solution Advice
  • Update XWiki to the latest version where this vulnerability is patched.
  • Ensure proper authentication mechanisms are in place for accessing REST API endpoints.
  • Conduct regular security audits to identify and mitigate potential vulnerabilities.
  • Restrict access to sensitive endpoints to only authorized personnel.
  • Consider implementing additional logging and monitoring to detect unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.