Known CVE
XWiki REST API - Attachments Disclosure
A vulnerability in XWiki's REST API allows unauthenticated users to access attachments list and metadata through the attachments endpoint. This could lead to disclosure of sensitive information stored in attachments metadata.
CVE-2025-46554
High2025CVSS 7.5CWE-285
cve2025 · xwiki · rest-api · exposure · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website