CVE-2025-65091
EUVD-2026-169910.01.2026, 04:16
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been patched in version 2.4.5.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| xwiki | full_calendar_macro | 𝑥 < 2.4.5 |
𝑥
= Vulnerable software versions