← Vulnerability feed

Vulnerability record · CVE-2025-32429 · published 24 July 2025

CVE-2025-32429: XWiki Platform SQL injection via sort parameter in getdeleteddocuments.vm

Xwiki · Xwiki

XWiki Platform fails to sanitize the sort parameter of getdeleteddocuments.vm, injecting it directly as an ORDER BY value. This allows unauthenticated SQL injection across a wide range of versions (9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2). The flaw is critical because it enables full read and write access to the backend database without any credentials.

9.3 CVSS 4.0 Critical EPSS 87% · top 0.3% CWE-89 · SQL injection
9.3CVSS 4.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 4.0 score of 9.3 with no authentication or user interaction required, combined with a very high EPSS probability, makes this an urgent remote SQL injection risk.

What it is

XWiki Platform fails to sanitize the sort parameter of getdeleteddocuments.vm, injecting it directly as an ORDER BY value. This allows unauthenticated SQL injection across a wide range of versions (9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2). The flaw is critical because it enables full read and write access to the backend database without any credentials.

Impact

An attacker can read, modify, or delete arbitrary data in the XWiki database, including user credentials and wiki content. This can lead to full compromise of the wiki instance and any data it stores.

Attack surface

The vulnerability is reachable over the network via the getdeleteddocuments.vm endpoint, with no authentication or user interaction required per the CVSS vector (PR:N, UI:N). Any remote client that can reach the XWiki web interface can send a crafted sort parameter.

Exploitation

The CVE is not listed in CISA KEV and no ransomware groups are documented using it. EPSS probability is 0.85265 (99.7th percentile), indicating a high likelihood of exploitation in the wild, though no public exploit code is referenced in the provided tags.

What to do

  • Upgrade to XWiki 16.10.6 or 17.3.0-rc-1 or later, which contain the fix.
  • If immediate upgrade is not possible, restrict network access to the getdeleteddocuments.vm endpoint to trusted users only.
  • Apply input validation or parameterized queries to the sort parameter as a temporary workaround if code changes are feasible.
  • Monitor XWiki security advisories and apply future patches promptly.
  • Review database logs for anomalous ORDER BY clauses or unexpected query patterns.

Detection

  • Search web server logs for requests to getdeleteddocuments.vm with unusual or malformed sort parameter values (e.g., containing SQL keywords, quotes, or comments).
  • Enable and review database audit logs for queries with unexpected ORDER BY clauses or errors indicative of SQL injection attempts.
  • Deploy WAF rules to block SQL injection patterns targeting the sort parameter on the getdeleteddocuments.vm endpoint.
  • Monitor for unexpected changes to wiki content or user accounts that could indicate successful exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-32429 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2025-32429), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.