A vulnerability in XWiki's XML view functionality exposes sensitive information such as passwords and email addresses that are stored in custom fields not explicitly named as password or email. This information disclosure occurs when accessing user profiles with the xml.vm template.
id: CVE-2025-54125
info:
name: XWiki XML View - Sensitive Information Exposure
author: ritikcha
...