XWiki Platform 4.2-milestone-2 through 16.10.6 contains a path traversal caused by improper access control in jsx and sx endpoints, letting remote attackers read configuration files, exploit requires no special privileges.
        
        
        
 id: CVE-2025-55748
info:
  name: XWiki Platform - Path Traversal
  author: Redmomn
  severity: high
...