Known CVE
XWiki REST API Query - SQL Injection
A SQL injection vulnerability exists in XWiki's REST API query endpoint. An unauthenticated attacker can execute arbitrary SQL queries through the 'q' parameter by manipulating the HQL query, potentially leading to data exfiltration or system compromise.
CVE-2025-32969
Critical2025CVSS 9.8CWE-89
cve2025 · xwiki · sqli · rest-api · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website