XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService
Critical severity
GitHub Reviewed
Published
Jan 9, 2026
in
xwiki-contrib/macro-fullcalendar
•
Updated Jan 11, 2026
Package
Affected versions
<= 2.4.3
Patched versions
2.4.5
Description
Published to the GitHub Advisory Database
Jan 9, 2026
Reviewed
Jan 9, 2026
Published by the National Vulnerability Database
Jan 10, 2026
Last updated
Jan 11, 2026
Impact
Anyone who has view rights on the
Calendar.JSONServicepage, including guest users can exploit this vulnerability by accessing database info or starting a DoS attack.Workarounds
Remove the
Calendar.JSONServicepage. This will however break some functionalities.References
Jira issue:
For more information
If there are any questions or comments about this advisory:
References