Vulnerability record · CVE-2025-32429 · published 24 July 2025
CVE-2025-32429: XWiki Platform SQL injection via sort parameter in getdeleteddocuments.vm
Xwiki · Xwiki
XWiki Platform fails to sanitize the sort parameter of getdeleteddocuments.vm, injecting it directly as an ORDER BY value. This allows unauthenticated SQL injection across a wide range of versions (9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2). The flaw is critical because it enables full read and write access to the backend database without any credentials.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 score of 9.3 with no authentication or user interaction required, combined with a very high EPSS probability, makes this an urgent remote SQL injection risk.
What it is
XWiki Platform fails to sanitize the sort parameter of getdeleteddocuments.vm, injecting it directly as an ORDER BY value. This allows unauthenticated SQL injection across a wide range of versions (9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2). The flaw is critical because it enables full read and write access to the backend database without any credentials.
Impact
An attacker can read, modify, or delete arbitrary data in the XWiki database, including user credentials and wiki content. This can lead to full compromise of the wiki instance and any data it stores.
Attack surface
The vulnerability is reachable over the network via the getdeleteddocuments.vm endpoint, with no authentication or user interaction required per the CVSS vector (PR:N, UI:N). Any remote client that can reach the XWiki web interface can send a crafted sort parameter.
Exploitation
The CVE is not listed in CISA KEV and no ransomware groups are documented using it. EPSS probability is 0.85265 (99.7th percentile), indicating a high likelihood of exploitation in the wild, though no public exploit code is referenced in the provided tags.
What to do
- Upgrade to XWiki 16.10.6 or 17.3.0-rc-1 or later, which contain the fix.
- If immediate upgrade is not possible, restrict network access to the getdeleteddocuments.vm endpoint to trusted users only.
- Apply input validation or parameterized queries to the sort parameter as a temporary workaround if code changes are feasible.
- Monitor XWiki security advisories and apply future patches promptly.
- Review database logs for anomalous ORDER BY clauses or unexpected query patterns.
Detection
- Search web server logs for requests to getdeleteddocuments.vm with unusual or malformed sort parameter values (e.g., containing SQL keywords, quotes, or comments).
- Enable and review database audit logs for queries with unexpected ORDER BY clauses or errors indicative of SQL injection attempts.
- Deploy WAF rules to block SQL injection patterns targeting the sort parameter on the getdeleteddocuments.vm endpoint.
- Monitor for unexpected changes to wiki content or user accounts that could indicate successful exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-32429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-32429), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.