XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. This vulnerability is fixed in 17.9.0, 17.4.6, and 16.10.13.
References
| Link | Resource |
|---|---|
| https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.6 | Product Release Notes |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-74rh-c5rh-88vg | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Feb 2026, 19:22
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| First Time |
Xwiki
Xwiki xwiki |
|
| References | () https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.6 - Product, Release Notes | |
| References | () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-74rh-c5rh-88vg - Patch, Vendor Advisory |
12 Feb 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-12 21:16
Updated : 2026-02-19 19:22
NVD link : CVE-2026-26000
Mitre link : CVE-2026-26000
CVE.ORG link : CVE-2026-26000
JSON object : View
Products Affected
xwiki
- xwiki
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
