Home / Web Application Vulnerabilities / XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-16277)
The Image Import function in XWiki through 10.7 has XSS.