

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (in…
Published:
9 January 2026 at 23:00:00
Alert date:
10 January 2026 at 13:10:58
Source:
nvd.nist.gov
CVE-2025-65091 affects XWiki Full Calendar Macro prior to version 2.4.5, allowing users with view rights to the Calendar.JSONService page (including guest users) to exploit a SQL injection vulnerability. The vulnerability enables attackers to access database information or launch denial of service attacks. This represents a significant security risk as guest users can potentially compromise the system without authentication. The issue has been patched in version 2.4.5.
Technical details
Mitigation steps:
Affected products:
XWiki Full Calendar Macro
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-65091
https://github.com/xwiki-contrib/macro-fullcalendar/commit/5fdcf06a05015786492fda69b4d9dea5460cc994
https://github.com/xwiki-contrib/macro-fullcalendar/security/advisories/GHSA-2g22-wg49-fgv5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

