S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 29, 2025

CVE-2025-29925 Scanner

CVE-2025-29925 Scanner - Information Disclosure vulnerability in XWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-29925
8.7
CVSShigh
Exploitable remotely over the internet · no authentication required.

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xwiki-platformby xwiki
>= 1.9M1, < 15.10.14
Updated Aug 22, 2026View on NVD →
Detail

XWiki is an open-source platform primarily used for collaborating and creating knowledge management solutions. It is popular among businesses and educational institutions for documentation and information management. Developed in Java, XWiki can serve as a powerful tool for customizing and extending enterprise applications. The software's REST API facilitates seamless interaction with XWiki data, allowing for extensive integrations. Users employ XWiki for managing team projects, documenting processes, and sharing knowledge across varied domains. Its extensibility and flexibility make it a preferred choice for organizations seeking customizable knowledge management solutions.

The Information Disclosure vulnerability in XWiki's REST API allows unauthorized access to private pages. This flaw resides in the API's pages endpoint, which can inadvertently expose sensitive information. As unauthenticated users can exploit this vulnerability, it poses a significant risk to data confidentiality. The issue is concerning for organizations as it can lead to unintended leaks of private page metadata. By exploiting this flaw, attackers could gather intelligence that might otherwise be restricted. Addressing this vulnerability is crucial to safeguard sensitive information from unauthorized access.

The vulnerability arises due to inadequate access control mechanisms in XWiki's REST API. Specifically, the endpoint intended for page retrieval fails to enforce proper authentication checks. Technical details reveal that endpoints like /rest/wikis/xwiki/pages?space= can be queried to uncover private page information. This loophole allows unauthorized parties to invoke the API and retrieve page summaries, metadata, and related elements. Security assessments should focus on the API responses, ensuring they don't include unauthorized data. The vulnerable paths must be audited and corrected to prevent exposure of restricted information.

Exploiting this vulnerability can lead to the unauthorized disclosure of sensitive private page details. Malicious actors capable of accessing this data might use it for reconnaissance or crafting targeted attacks. Businesses could suffer from information leaks, damaging their reputation and leading to a loss of competitive advantage. The lack of stringent access control might also mean potential violations of data protection regulations. The exposure also increases the risk of social engineering, where private information about internal processes could be misused. Ultimately, this vulnerability underscores the need for rigorous security controls on API endpoints to maintain data confidentiality.

Solution Advice
  • Implement strict access control measures on all REST API endpoints to restrict access to authenticated users only.
  • Regularly audit and review API permissions to ensure they align with organizational data security policies.
  • Update XWiki to the latest version to incorporate any patches or security fixes related to API vulnerabilities.
  • Conduct regular security assessments and penetration testing of API endpoints to identify and remediate potential exposures.
  • Ensure detailed logging and monitoring of API access to detect any unauthorized attempts in real-time.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.