XWiki Platform Clickjacking Vulnerability via CSS Injection in Comments

Vulnerability

A clickjacking vulnerability has been identified in XWiki Platform versions prior to 17.9.0, 17.4.6, and 16.10.13. This issue allows users to inject CSS through comments, which can then be used to manipulate the appearance of the wiki, creating a deceptive link area that directs to a malicious page. All XWiki versions are susceptible to this type of attack.

Impact

Exploitation of this vulnerability could lead to clickjacking, where a user is tricked into interacting with a page element that is different from what they perceive.

Remediation

Users can update to XWiki Platform versions 17.9.0, 17.4.6, or 16.10.13 to address this vulnerability. For those unable to update, it may be possible to implement a partial workaround using the JavaScript code available in the XWiki 17.9.0 release, which can be reused in a JSX object within the wiki to request confirmation before clicking on links to untrusted domains.

Added: Feb 12, 2026, 9:18 PM
Updated: Feb 12, 2026, 9:18 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.2
exploitability
5.0
remediation
7.7
relevance
2.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.