CVE-2026-24128: XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
(updated )
A reflected cross site scripting (XSS) vulnerability in XWiki allows an attacker to execute arbitrary actions in XWiki with the rights of the victim if the attacker manages to trick a victim into visiting a crafted URL. If the victim has administrative or programming rights, those rights can be exploited to gain full access to the XWiki installation.
References
- github.com/advisories/GHSA-wvqx-m5px-6cmp
- github.com/xwiki/xwiki-platform
- github.com/xwiki/xwiki-platform/commit/8337ac8c3b19c37f306723b638b2cae8b0a57dbf
- github.com/xwiki/xwiki-platform/commit/8337ac8c3b19c37f306723b638b2cae8b0a57dbf
- github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-16.10.12
- github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.5
- github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.8.0-rc-1
- github.com/xwiki/xwiki-platform/security/advisories/GHSA-wvqx-m5px-6cmp
- jira.xwiki.org/browse/XWIKI-23462
- nvd.nist.gov/vuln/detail/CVE-2026-24128
Code Behaviors & Features
Detect and mitigate CVE-2026-24128 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →