XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Sep 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xwiki xwiki
|
|
CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xwiki xwiki
|
Sun, 31 Aug 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xwiki
Xwiki xwiki-platform |
|
Vendors & Products |
Xwiki
Xwiki xwiki-platform |
Thu, 28 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 28 Aug 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1. | |
Title | XWiki PDF export jobs store sensitive cookies unencrypted in job statuses | |
Weaknesses | CWE-212 CWE-257 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-28T18:15:47.326Z
Reserved: 2025-08-22T14:30:32.221Z
Link: CVE-2025-58049

Updated: 2025-08-28T18:15:44.139Z

Status : Analyzed
Published: 2025-08-28T18:15:33.657
Modified: 2025-09-02T17:34:25.467
Link: CVE-2025-58049

No data.

Updated: 2025-08-31T08:41:42Z