XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService
Moderate severity
GitHub Reviewed
Published
Jan 9, 2026
in
xwiki-contrib/macro-fullcalendar
•
Updated Jan 11, 2026
Package
Affected versions
<= 2.4.5
Patched versions
2.4.6
Description
Published to the GitHub Advisory Database
Jan 9, 2026
Reviewed
Jan 9, 2026
Published by the National Vulnerability Database
Jan 10, 2026
Last updated
Jan 11, 2026
Impact
Anyone who has view rights on the
Calendar.JSONServicepage, including guest users can exploit this vulnerability by accessing database info, with the exception of passwords.Workarounds
Remove the
Calendar.JSONServicepage. This will however break some functionalities.References
Jira issue:
For more information
If you have any questions or comments about this advisory:
References