Skip to content

Known CVE

XWiki REST API - Attachments Disclosure

A vulnerability in XWiki's REST API allows unauthenticated users to access attachments list and metadata through the attachments endpoint. This could lead to disclosure of sensitive information stored in attachments metadata.

CVE-2025-46554

High2025CVSS 7.5CWE-285

cve2025 · xwiki · rest-api · exposure · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website