XWiki Platform is vulnerable to reflected XSS via the previewactions template. An attacker can inject JavaScript through the xcontinue parameter.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view