XWiki Platform Distribution Flavor Main - Cross-Site Scripting
CVE-2026-24128
Verified
Description
XWiki Platform Distribution Flavor Main versions prior to 17.6.0 are vulnerable to reflected cross-site scripting (XSS) due to improper sanitization of user-supplied input in the extensionId parameter. An attacker can exploit this issue by injecting malicious JavaScript, which will be executed in the context of the victim's browser, potentially leading to session hijacking or other attacks.
Severity
Medium
CVSS Score
6.1
Exploit Probability
1%
Affected Product
xwiki-platform-distribution-flavor-main
Published Date
January 28, 2026
Template Author
ritikchaddha
CVE-2026-24128.yaml
6.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE ID:
cve-2026-24128
CWE ID:
cwe-79