XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
Metrics
Affected Vendors & Products
References
History
Mon, 12 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki xwiki |
|
| Vendors & Products |
Xwiki
Xwiki xwiki |
Sat, 10 Jan 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6. | |
| Title | XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-10T03:05:06.531Z
Updated: 2026-01-12T17:36:38.233Z
Reserved: 2025-11-17T20:55:34.691Z
Link: CVE-2025-65090
Updated: 2026-01-12T17:36:35.064Z
Status : Received
Published: 2026-01-10T04:16:01.013
Modified: 2026-01-10T04:16:01.013
Link: CVE-2025-65090
No data.