CVE 5.3 MEDIUM

XWiki Platform affected by click-jacking through CSS injection in comments_CVE-2026-26000

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. This vulnerability is fixed in 17.9.0, 17.4.6, and 16.10.13.

Basic Information

ID CVE-2026-26000
Source GitHub_M
Published Feb 12, 2026 at 20:30

Affected Product

Vendor xwiki
Product xwiki-platform
Version >= 17.5.0, < 17.9.0
Affected Versions xwiki xwiki-platform >= 17.5.0, < 17.9.0
xwiki xwiki-platform >= 17.0.0-rc-1, < 17.4.6
xwiki xwiki-platform < 16.10.13

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.