{"id":"CVE-2025-54125","aliases":["GHSA-57q2-6cp4-9mq3"],"url":"https://o3.security/vulnerability/CVE-2025-54125","summary":"XWiki Platform: Password and email exposure in xml.vm fields","details":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1.0, the XML export of a page in XWiki that can be triggered by any user with view rights on a page by appending ?xpage=xml to the URL includes password and email properties stored on a document that aren't named password or email. This is fixed in versions 16.4.7, 16.10.5 and 17.2.0-rc-1. To work around this issue, the file templates/xml.vm in the deployed WAR can be deleted if the XML isn't needed. There isn't any feature in XWiki itself that depends on the XML export.","published":"2025-08-05T23:30:38.963Z","modified":"2026-08-08T09:04:51.900940Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"16.4.7"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"16.10.5"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-oldcore","fixedVersion":"17.2.0-rc-1"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-legacy-oldcore","fixedVersion":"16.4.7"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-legacy-oldcore","fixedVersion":"16.10.5"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-legacy-oldcore","fixedVersion":"17.2.0-rc-1"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/742ee3482ef6c2bd4ad03d0de9cdd81d0e8f3d59","label":"xwiki/xwiki-platform@742ee34"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-22810"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54125.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-57q2-6cp4-9mq3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54125"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/742ee3482ef6c2bd4ad03d0de9cdd81d0e8f3d59"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T09:04:51.900940Z"}}