PT-2026-7901 · Xwiki · Xwiki Platform

Keechy1231

·

Published

2026-02-12

·

Updated

2026-02-20

·

CVE-2026-26000

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 17.9.0 XWiki Platform versions prior to 17.4.6 XWiki Platform versions prior to 16.10.13
Description The XWiki Platform, a generic wiki platform, is affected by a UI redressing issue, specifically a clickjacking attack. This allows unauthenticated attackers to hijack user clicks through CSS injection within comments. By overlaying invisible anchor elements, an attacker can redirect users to malicious pages. The issue stems from improper restriction of visual layers within the user interface. The vulnerability allows for CSS injection using the comment functionality.
Recommendations Update to XWiki Platform version 17.9.0 or later. Update to XWiki Platform version 17.4.6 or later. Update to XWiki Platform version 16.10.13 or later.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

BDU:2026-02020
CVE-2026-26000
GHSA-74RH-C5RH-88VG

Affected Products

Xwiki Platform