Skip to main content
Vulnerability Database/CVE-2025-52132

CVE-2025-52132: Mocca Calendar XWiki XSS Vulnerability

CVE-2025-52132 is a cross-site scripting flaw in Mocca Calendar for XWiki that allows attackers to inject malicious scripts through event titles. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-52132 Overview

CVE-2025-52132 is a stored cross-site scripting (XSS) vulnerability in the Mocca Calendar application for XWiki. The flaw affects all versions of Mocca Calendar before 2.15. An authenticated attacker can inject malicious JavaScript through the title field of a calendar event. The payload executes in the browser of any user who views the event page. The vulnerability is classified as [CWE-79] Improper Neutralization of Input During Web Page Generation.

Critical Impact

Authenticated attackers can inject arbitrary JavaScript that executes in the context of victims' sessions, enabling session hijacking, credential theft, and unauthorized actions against the XWiki instance.

Affected Products

  • Mocca Calendar application for XWiki versions prior to 2.15
  • XWiki instances with the application-mocca-calendar extension installed
  • Both xwiki-contrib and xwikisas distributions of Mocca Calendar

Discovery Timeline

  • 2025-08-03 - CVE-2025-52132 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-52132

Vulnerability Analysis

The vulnerability resides in the Mocca Calendar extension for XWiki, a collaborative wiki platform. Mocca Calendar allows users to create and manage calendar events within XWiki spaces. When a user creates an event, the application accepts a title value and later renders it on the view event page.

The rendering path fails to sanitize or HTML-encode the title before insertion into the page markup. As a result, an attacker with permission to create or edit events can supply a title containing script content. When any user opens the event view page, the browser parses and executes the injected script under the origin of the XWiki instance.

Exploitation requires low privileges because event creation is a standard user action in Mocca Calendar. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component, including the broader XWiki application session.

Root Cause

The root cause is missing output encoding of user-controlled data in the view event template. The title field is stored verbatim and rendered without applying XWiki's HTML escaping utilities, allowing HTML and JavaScript tags to be interpreted rather than displayed as text.

Attack Vector

An authenticated attacker creates or edits a Mocca Calendar event and places a JavaScript payload inside the title field. When another user, including an administrator, navigates to the view event page, the payload executes in that user's browser session. The attacker can then exfiltrate session cookies, perform actions on behalf of the victim, or pivot to further attacks within the wiki.

No verified proof-of-concept code is publicly available. Refer to the GitHub Security Advisory GHSA-fjv4-pgh9-jfgc for maintainer-supplied technical details.

Detection Methods for CVE-2025-52132

Indicators of Compromise

  • Calendar event titles containing HTML tags such as <script>, <img onerror=>, or <svg onload=> stored in the XWiki database
  • Unexpected outbound requests from user browsers to attacker-controlled domains after viewing calendar events
  • Session tokens or CSRF tokens appearing in web server or proxy logs as query string parameters
  • Unauthorized administrative actions performed shortly after users view calendar event pages

Detection Strategies

  • Query the XWiki database for Mocca Calendar event documents whose title fields contain angle brackets or JavaScript event handlers
  • Enable and monitor Content Security Policy (CSP) violation reports for inline script execution on calendar view endpoints
  • Review XWiki access logs for POST or PUT requests to Mocca Calendar event endpoints containing script-like payloads in form data

Monitoring Recommendations

  • Alert on HTTP requests to Mocca Calendar event view URLs that produce responses containing unescaped user input
  • Monitor for anomalous session activity following access to calendar event pages, particularly privileged account behavior
  • Track version metadata for the application-mocca-calendar extension across all XWiki deployments to identify unpatched instances

How to Mitigate CVE-2025-52132

Immediate Actions Required

  • Upgrade the Mocca Calendar extension to version 2.15 or later on all XWiki instances
  • Audit existing calendar events for titles containing HTML or script content and remove suspicious entries
  • Rotate session tokens and force reauthentication for users who may have viewed malicious event pages
  • Review Mocca Calendar edit permissions and restrict event creation to trusted users where feasible

Patch Information

The vulnerability is fixed in Mocca Calendar version 2.15. Update the extension through the XWiki Extension Manager or by pulling the patched release from the xwikisas GitHub repository or the xwiki-contrib GitHub repository. Refer to the XWiki Extension page for Mocca Calendar for installation details.

Workarounds

  • Deploy a strict Content Security Policy that disallows inline scripts on XWiki pages to limit XSS impact
  • Temporarily disable the Mocca Calendar extension in environments where immediate patching is not possible
  • Restrict edit rights on calendar event pages to a limited set of trusted administrators until the patch is applied
bash
# Configuration example: strict CSP header for XWiki reverse proxy
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'";

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.