Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-53gx-j3p6-2rw9 | XWiki Jetty Package (XJetty) allows accessing any application file through URL |
Mon, 02 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xwiki wiki-platform
|
Fri, 06 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki wiki-platform
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:xwiki:wiki-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xwiki wiki-platform
|
|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki xwiki Xwiki xwiki-platform |
|
| Vendors & Products |
Xwiki
Xwiki xwiki Xwiki xwiki-platform |
Mon, 01 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows accessing files which might contains credentials. Fixed in 16.10.11, 17.4.4, and 17.7.0. | |
| Title | The XWiki Jetty package (XJetty) allows accessing any application file through URL | |
| Weaknesses | CWE-284 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-01T20:34:50.797Z
Reserved: 2025-08-14T22:31:17.685Z
Link: CVE-2025-55749
Updated: 2025-12-01T20:26:26.595Z
Status : Analyzed
Published: 2025-12-01T21:15:51.617
Modified: 2026-03-02T22:02:46.253
Link: CVE-2025-55749
No data.
OpenCVE Enrichment
Updated: 2025-12-02T11:58:46Z
Github GHSA