XWiki 16.7.0 to 16.10.11, 17.4.4, and 17.7.0 using XJetty contains an information disclosure vulnerability caused by exposed context allowing static access to files in webapp/ folder, letting attackers access sensitive files, exploit requires use of XJetty package.
id: CVE-2025-55749
info:
name: XWiki - Information Disclosure
author: DhiyaneshDk
severity: h
...