CVE-2025-65090: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in xwiki-contrib macro-fullcalendar
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2025-65090 affects the macro-fullcalendar component of the xwiki-contrib project, specifically versions prior to 2.4.6. This component integrates calendar functionalities within XWiki, displaying wiki objects on a calendar interface. The flaw arises because users with the ability to view the Calendar.JSONService page—including unauthenticated guest users—can access sensitive database information through this service. Although passwords are excluded, other sensitive data stored in the database can be exposed, constituting an information disclosure vulnerability categorized under CWE-200. The vulnerability is exploitable remotely without any authentication or user interaction, increasing its risk profile. The CVSS v3.1 base score is 5.3, reflecting a medium severity primarily due to the confidentiality impact without affecting integrity or availability. The vulnerability was publicly disclosed in January 2026 and has been addressed by patching in version 2.4.6 of the macro-fullcalendar. No known exploits have been reported in the wild, but the ease of exploitation and the exposure of sensitive information make timely patching essential. The vulnerability's root cause is insufficient access control on the Calendar.JSONService endpoint, allowing unauthorized data retrieval.
Potential Impact
For European organizations, this vulnerability poses a risk of sensitive information leakage from XWiki deployments using the macro-fullcalendar component. Although passwords are not exposed, other confidential data stored in the wiki database could be accessed by unauthorized parties, potentially leading to information disclosure that could facilitate further attacks such as social engineering or targeted intrusions. Organizations relying on XWiki for collaboration, documentation, or knowledge management could face reputational damage, compliance issues under GDPR due to unauthorized data exposure, and operational risks if sensitive business information is leaked. The vulnerability's remote and unauthenticated exploitability increases the likelihood of opportunistic scanning and exploitation, especially in publicly accessible XWiki instances. The impact is more pronounced for sectors with strict data protection requirements, such as finance, healthcare, and government agencies within Europe.
Mitigation Recommendations
The primary and most effective mitigation is to upgrade the macro-fullcalendar component to version 2.4.6 or later, where the vulnerability is patched. Organizations should audit their XWiki instances to identify affected versions and prioritize patching accordingly. If immediate upgrading is not feasible, restrict access to the Calendar.JSONService page by implementing network-level controls such as IP whitelisting or VPN access, and adjust XWiki permissions to limit viewing rights to trusted authenticated users only. Additionally, monitor logs for unusual access patterns to the Calendar.JSONService endpoint to detect potential exploitation attempts. Conduct regular security assessments and ensure that sensitive data stored in the wiki is classified and access-controlled appropriately. Employ web application firewalls (WAFs) with rules targeting suspicious requests to the vulnerable endpoint as a temporary protective measure.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy, Spain, Sweden
CVE-2025-65090: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in xwiki-contrib macro-fullcalendar
Description
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
AI-Powered Analysis
Technical Analysis
The vulnerability identified as CVE-2025-65090 affects the macro-fullcalendar component of the xwiki-contrib project, specifically versions prior to 2.4.6. This component integrates calendar functionalities within XWiki, displaying wiki objects on a calendar interface. The flaw arises because users with the ability to view the Calendar.JSONService page—including unauthenticated guest users—can access sensitive database information through this service. Although passwords are excluded, other sensitive data stored in the database can be exposed, constituting an information disclosure vulnerability categorized under CWE-200. The vulnerability is exploitable remotely without any authentication or user interaction, increasing its risk profile. The CVSS v3.1 base score is 5.3, reflecting a medium severity primarily due to the confidentiality impact without affecting integrity or availability. The vulnerability was publicly disclosed in January 2026 and has been addressed by patching in version 2.4.6 of the macro-fullcalendar. No known exploits have been reported in the wild, but the ease of exploitation and the exposure of sensitive information make timely patching essential. The vulnerability's root cause is insufficient access control on the Calendar.JSONService endpoint, allowing unauthorized data retrieval.
Potential Impact
For European organizations, this vulnerability poses a risk of sensitive information leakage from XWiki deployments using the macro-fullcalendar component. Although passwords are not exposed, other confidential data stored in the wiki database could be accessed by unauthorized parties, potentially leading to information disclosure that could facilitate further attacks such as social engineering or targeted intrusions. Organizations relying on XWiki for collaboration, documentation, or knowledge management could face reputational damage, compliance issues under GDPR due to unauthorized data exposure, and operational risks if sensitive business information is leaked. The vulnerability's remote and unauthenticated exploitability increases the likelihood of opportunistic scanning and exploitation, especially in publicly accessible XWiki instances. The impact is more pronounced for sectors with strict data protection requirements, such as finance, healthcare, and government agencies within Europe.
Mitigation Recommendations
The primary and most effective mitigation is to upgrade the macro-fullcalendar component to version 2.4.6 or later, where the vulnerability is patched. Organizations should audit their XWiki instances to identify affected versions and prioritize patching accordingly. If immediate upgrading is not feasible, restrict access to the Calendar.JSONService page by implementing network-level controls such as IP whitelisting or VPN access, and adjust XWiki permissions to limit viewing rights to trusted authenticated users only. Additionally, monitor logs for unusual access patterns to the Calendar.JSONService endpoint to detect potential exploitation attempts. Conduct regular security assessments and ensure that sensitive data stored in the wiki is classified and access-controlled appropriately. Employ web application firewalls (WAFs) with rules targeting suspicious requests to the vulnerable endpoint as a temporary protective measure.
Affected Countries
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2025-11-17T20:55:34.691Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6961cb1719784dcf52be20d8
Added to database: 1/10/2026, 3:44:23 AM
Last enriched: 1/10/2026, 3:59:05 AM
Last updated: 1/10/2026, 9:25:52 PM
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2026-0824: Cross Site Scripting in questdb ui
MediumCVE-2025-13393: CWE-918 Server-Side Request Forgery (SSRF) in marceljm Featured Image from URL (FIFU)
MediumCVE-2025-12379: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in averta Shortcodes and extra features for Phlox theme
MediumCVE-2026-0822: Heap-based Buffer Overflow in quickjs-ng quickjs
MediumCVE-2026-0821: Heap-based Buffer Overflow in quickjs-ng quickjs
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.