XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-637h-ch24-xp9m | XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Jan 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6. | |
| Title | XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-10T03:06:03.471Z
Reserved: 2025-11-17T20:55:34.691Z
Link: CVE-2025-65090
No data.
Status : Received
Published: 2026-01-10T04:16:01.013
Modified: 2026-01-10T04:16:01.013
Link: CVE-2025-65090
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA