XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
History

Mon, 12 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki xwiki
Vendors & Products Xwiki
Xwiki xwiki

Sat, 10 Jan 2026 03:45:00 +0000

Type Values Removed Values Added
Description XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
Title XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-01-10T03:05:06.531Z

Updated: 2026-01-12T17:36:38.233Z

Reserved: 2025-11-17T20:55:34.691Z

Link: CVE-2025-65090

cve-icon Vulnrichment

Updated: 2026-01-12T17:36:35.064Z

cve-icon NVD

Status : Received

Published: 2026-01-10T04:16:01.013

Modified: 2026-01-10T04:16:01.013

Link: CVE-2025-65090

cve-icon Redhat

No data.