CVE-2026-26000 PUBLISHED

XWiki Platform affected by click-jacking through CSS injection in comments

Assigner: GitHub_M
Reserved: 09.02.2026 Published: 12.02.2026 Updated: 12.02.2026

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. This vulnerability is fixed in 17.9.0, 17.4.6, and 16.10.13.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor xwiki
Product xwiki-platform
Versions
  • Version >= 17.5.0, < 17.9.0 is affected
  • Version >= 17.0.0-rc-1, < 17.4.6 is affected
  • Version < 16.10.13 is affected

References

Problem Types

  • CWE-1021: Improper Restriction of Rendered UI Layers or Frames CWE