
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66472 is a reflected Cross-Site Scripting (XSS) vulnerability in XWiki, specifically in the xredirect parameter of the DeleteApplication feature. An unauthenticated attacker can craft a malicious URL that, when visited by a victim who clicks the "No" button on a deletion confirmation dialog, executes attacker-supplied JavaScript in the victim's browser. The vulnerability affects XWiki versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1. It was disclosed on December 10, 2025, with a CVSS v3.1 score of 6.1 (Medium) and a CVSS v4.0 score of 6.5 (Medium) (Github Advisory, XWiki Security Advisory).
The root cause is improper neutralization of script-related HTML tags in a web page (CWE-79, CWE-80). The xredirect URL parameter used in XWiki's deletion confirmation templates (macros.vm in both xwiki-platform-flamingo-skin-resources and xwiki-platform-web-templates) was rendered without proper sanitization, allowing attacker-controlled content to be injected into the HTML of the confirmation page. The fix (commit cb578b1) restructured the confirmation dialog to use the xredirect parameter only in its intended context — as a redirect URL — rather than rendering it directly as HTML content, eliminating the injection point (XWiki Security Advisory, Patch Commit).
When exploited against a victim with admin or programming rights, this vulnerability effectively enables remote code execution on the XWiki installation, as XWiki's scripting engine allows privileged users to execute arbitrary server-side code. An attacker could leverage this to modify system configurations, create unauthorized user accounts, exfiltrate sensitive wiki content, or fully compromise the XWiki instance. Even against lower-privileged users, the XSS can be used to steal session tokens or perform unauthorized actions within the victim's session (Github Advisory).
A proof-of-concept exploit reference is available via the XWiki Jira issue tracker (XWIKI-23244), and a Nuclei detection template has been developed and merged into the ProjectDiscovery nuclei-templates repository. There is no confirmed evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.039% (0.095% per GitHub Advisory), indicating low but non-negligible exploitation probability. The vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution has been reported (Github Advisory, XWiki Jira).
xredirect parameter, e.g., https://target-xwiki.example.com/xwiki/bin/delete/App/WebHome?xredirect=javascript:alert(document.cookie) or a more complex payload encoded to bypass basic filters./xwiki/bin/delete/) containing suspicious xredirect parameter values with JavaScript schemes (javascript:), encoded script tags, or unusual URL-encoded characters.xredirect parameter values; repeated requests from external referrers or unfamiliar IP addresses targeting deletion endpoints.XWiki has released patches in versions 16.10.10, 17.4.2, and 17.5.0. Administrators should upgrade to one of these versions as the primary remediation. For those unable to upgrade immediately, the patch can be manually applied to the affected Velocity templates (macros.vm in both xwiki-platform-flamingo-skin-resources and xwiki-platform-web-templates) present in the WAR file, followed by a restart of XWiki. Additionally, restricting admin and programming rights to only essential users reduces the potential impact of exploitation (Github Advisory, Patch Commit).
The vulnerability was reported by security researcher 4rdr and published by XWiki maintainer michitux on December 10, 2025. A Nuclei detection template was subsequently contributed to the ProjectDiscovery nuclei-templates repository, indicating community interest in automated detection. Social media activity on Bluesky referenced the CVE, and it was picked up by standard vulnerability aggregators. No major vendor statements beyond the XWiki advisory or significant media coverage have been identified (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."