A SQL injection vulnerability exists in XWiki's REST API query endpoint. An unauthenticated attacker can execute arbitrary SQL queries through the 'q' parameter by manipulating the HQL query, potentially leading to data exfiltration or system compromise.
id: CVE-2025-32969
info:
name: XWiki REST API Query - SQL Injection
author: ritikchaddha
seve
...