Cross-site scripting in XWiki platform - CVE-2025-32430
Published: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to execute malicious JavaScript code in the context of the victim's session.
The vulnerability exists due to cross-site scripting in two web templates when handling attacker-controlled URL parameters. A remote attacker can send a specially crafted URL to execute malicious JavaScript code in the context of the victim's session.
User interaction is required to visit an attacker-controlled URL, which can allow arbitrary actions using the permissions of the victim.