Exposure of Private Information ('Privacy Violation') in XWiki platform - CVE-2025-54124
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in database list properties when referencing password properties. A remote user can create an XClass with a database list property that references a password property and add an object of that XClass to disclose sensitive information.
In practice, with a standard rights setup, any user with an account on the wiki can access password hashes of all users, and possibly other password properties on pages that the user can view.