CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-66472

MEDIUM
6.5
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-12-10
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates are vulnerable to a reflected XSS attack through a deletion confirmation message. The attacker-supplied script is executed when the victim clicks the "No" button. This issue is fixed in versions 16.10.10 and 17.4.2 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates.

Affected Platforms (CPE)

📦
Xwiki

Xwiki

>= 6.2 and < 16.10.10>= 17.0.0 and < 17.4.2

References & Advisories

相關漏洞威脅