XWiki Platform 4.2-milestone-2 through 16.10.6 contains a path traversal caused by improper access control in jsx and sx endpoints, letting remote attackers read configuration files, exploit requires no special privileges.
id: CVE-2025-55748
info:
name: XWiki Platform - Path Traversal
author: Redmomn
severity: high
...