CVE-2026-26000

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. This vulnerability is fixed in 17.9.0, 17.4.6, and 16.10.13.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*

History

19 Feb 2026, 19:22

Type Values Removed Values Added
CPE cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Xwiki
Xwiki xwiki
References () https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.6 - () https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.6 - Product, Release Notes
References () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-74rh-c5rh-88vg - () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-74rh-c5rh-88vg - Patch, Vendor Advisory

12 Feb 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 21:16

Updated : 2026-02-19 19:22


NVD link : CVE-2026-26000

Mitre link : CVE-2026-26000

CVE.ORG link : CVE-2026-26000


JSON object : View

Products Affected

xwiki

  • xwiki
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames