XWikiplatform Incorrect Authorization Vulnerability - CVE-2025-29924
XWiki Platform is a generic wiki platform. Prior to 15.10.14 16.4.6 and 16.10.0-rc-1 it39s possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using quotPrevent unregistered users to view pagesquot. The vulnerability only affects subwikis and it only concerns specific right options such as quotPrevent unregistered users to view pagesquot. or quotPrevent unregistered users to edit pagesquot. It39s possible to detect the vulnerability by enabling quotPrevent unregistered users to view pagesquot and then trying to access a page through the REST API without using any credentials. The vulnerability has been patched in XWiki 15.10.14 16.4.6 and 16.10.0RC1.