CVE Explorer
CVE-2025-66473
XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single request at the moment. Depending on the number of pages in the wiki and the memory configuration, this can lead to slowness and unavailability of the wiki. As an example, the /rest/wikis/xwiki/spaces resource returns all spaces on the wiki by default, whi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"xwiki-platform","vendor":"xwiki","versions":[{"status":"affected","version":"< 16.10.11"},{"status":"affected","version":">= 17.0.0-rc-1, < 17.4.4"},{"status":"affected","version":">= 17.5.0-rc-1, < 17.7.0-rc-1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a9b97a4ac777fb3f0e1a0020b377b32438b05d869d32a4dff5d549bb56c4b312 · sha256:f8f976c6f335e68e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a9b97a4ac777fb3f0e1a0020b377b32438b05d869d32a4dff5d549bb56c4b312 · sha256:f8f976c6f335e68e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-770","description":"CWE-770: Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a9b97a4ac777fb3f0e1a0020b377b32438b05d869d32a4dff5d549bb56c4b312 · sha256:f8f976c6f335e68e… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/xwiki/xwiki-platform/commit/e3c47745195fb445b054537be86f5c01ee69558b","tags":["x_refsource_MISC"],"url":"https://github.com/xwiki/xwiki-platform/commit/e3c47745195fb445b054537be86f5c01ee69558b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a9b97a4ac777fb3f0e1a0020b377b32438b05d869d32a4dff5d549bb56c4b312 · sha256:f8f976c6f335e68e… · /containers/cna/references/1
{"name":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-cc84-q3v3-mhgf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-cc84-q3v3-mhgf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a9b97a4ac777fb3f0e1a0020b377b32438b05d869d32a4dff5d549bb56c4b312 · sha256:f8f976c6f335e68e… · /containers/cna/references/0
{"name":"https://jira.xwiki.org/browse/XWIKI-23355","tags":["x_refsource_MISC"],"url":"https://jira.xwiki.org/browse/XWIKI-23355"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a9b97a4ac777fb3f0e1a0020b377b32438b05d869d32a4dff5d549bb56c4b312 · sha256:f8f976c6f335e68e… · /containers/cna/references/2
{"tags":["exploit"],"url":"https://jira.xwiki.org/browse/XWIKI-23355"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a9b97a4ac777fb3f0e1a0020b377b32438b05d869d32a4dff5d549bb56c4b312 · sha256:f8f976c6f335e68e… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.