CVE-2025-65090
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
- Affected products
- Xwiki
- Xwiki Full Calendar Macro
- < 2.4.6
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2026-01-10
CVE-2025-65090 at NVD
No indexed exploits for CVE-2025-65090 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-65090 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.