CVE-2026-40105General(xwiki / xwiki)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.5.0-rc-1 through 17.10.0 contain a reflected cross-site scripting vulnerability (XSS) in the comparison view between revisions of a page allows executing JavaScript code in the user's browser. If the current user is an admin, this can not only affect the current user but also the confidentiality, integrity and availability of the whole XWiki instance. If developers are unable to update immediately, they can apply the patch manually to templates/changesdoc.vm in the deployed WAR.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-80

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xwiki

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
xwiki

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-15: 1Mentions · 2026-05-04: 1PoC Mentioned / Linked · 2026-05-04: 1Technical Details · 2026-05-04: 104-1505-04
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-151
General1
2026-05-041
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-40105 - medium 🚨 XWiki - Cross-Site Scripting > XWiki is vulnerable to reflected Cross-Site Scripting (XSS) via the `viewer=changes` ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-40105 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a medium‑severity reflected XSS flaw in XWiki (CVE‑2026‑40105), provides a link to a project discovery library likely containing a PoC, but does not mention active exploitation or patches.

    00023178
    973 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40105 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 1… https://www.cve.org/CVERecord?id=CVE-2026-40105

    Post summary

    The passage merely lists the CVE identifier and a brief note on affected XWiki Platform versions, lacking any further technical, exploit, or mitigation information.

    0000051
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxwikixwiki---

Explore more