MEDIUM 6.1 Maven
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
GHSA-w4fj-87j5-f25c · CVE-2026-40105
Published · Modified
Description
Impact
A reflected cross-site scripting vulnerability (XSS) in the compare view between revisions of a page allows executing JavaScript code in the user's browser. If the current user is an admin, this can not only affect the current user but also the confidentiality, integrity and availability of the whole XWiki instance.
Patches
The problem has been patched by properly escaping the URL parameters.
Workarounds
The patch can be applied manually to templates/changesdoc.vm in the deployed WAR.
Attribution
XWiki thanks Mike Cole @mikecole-mg for discovering and reporting this vulnerability.
References
- WEB https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-w4fj-87j5-f25c
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-40105
- WEB https://github.com/xwiki/xwiki-platform/commit/3c8a2ec985641367015c2db937574fcd360c788c
- PACKAGE https://github.com/xwiki/xwiki-platform
- WEB https://jira.xwiki.org/browse/XWIKI-23472
Ready to move
Start Securing
Free, no credit card | First findings in minutes