Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.7

CVE-2025-48885: XWiki URL Shortener Creates Arbitrary Pages

CVE-2025-48885
Summary

Versions of XWiki's URL Shortener before 1.2.4 allow anyone to create new pages, even guests, which can clutter the wiki and make it hard for admins to manage. This can happen even if the page doesn't exist yet. Update to version 1.2.4 or later to fix this issue.

Original title
application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create arbitrary pages. Any user (even guests) can cre...
Original description
application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create arbitrary pages. Any user (even guests) can create these docs, even if they don't exist already. This can enable guest users to denature the structure of wiki pages, by creating 1000's of pages with random name, that then become very difficult to handle by admins. Version 1.2.4 fixes the issue. No known workarounds are available.
nvd CVSS4.0 5.7
Vulnerability type
CWE-352 Cross-Site Request Forgery (CSRF)
Published: 30 May 2025 · Updated: 27 Jun 2026 · First seen: 7 Mar 2026