A vulnerability in XWiki's REST API allows unauthenticated users to access information about private pages through the pages endpoint. This could lead to disclosure of sensitive information and page metadata.
id: CVE-2025-29925
info:
name: XWiki REST API - Private Pages Disclosure
author: ritikchaddha
...