XWiki through version 17.3.0 contains stored cross-site scripting caused by improper sanitization of inputs in the Administration interface's Presentation section, letting authenticated administrators inject JavaScript that executes in visitors' browsers, exploit requires administrator authentication.
id: CVE-2025-51990
info:
name: XWiki – Stored Cross-Site Scripting (XSS)
author: 0x_Akoko
sev
...