XWiki Platform is vulnerable to reflected XSS via the previewactions template. An attacker can inject JavaScript through the xcontinue parameter.
id: CVE-2023-35162
info:
name: XWiki < 14.10.5 - Cross-Site Scripting
author: ritikchaddha
se
...