A vulnerability in XWiki's WYSIWYG API allows an attacker to redirect users to arbitrary external URLs through the xerror parameter. This could be used in phishing attacks to redirect users to malicious websites.
id: CVE-2025-32970
info:
name: XWiki WYSIWYG API - Open Redirect
author: ritikchaddha
severit
...