XWiki is vulnerable to reflected Cross-Site Scripting (XSS) via the `viewer=changes` endpoint. The `rev2` parameter is not properly sanitised before being rendered in the response, allowing an attacker to inject arbitrary JavaScript. Affects XWiki versions prior to the patched release.
id: CVE-2026-40105
info:
name: XWiki - Cross-Site Scripting
author: ritikchaddha
severity: me
...