We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-32069

Wikitext stored XSS on filepages due to dangerous WBMI serialization



Description

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Media Info Extension: from 1.39 through 1.43.

Reserved 2025-04-03 | Published 2025-04-11 | Updated 2025-04-11 | Assigner wikimedia-foundation


CRITICAL: 10.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

1.39
affected

Credits

Dylsss finder

matthiasmullie finder

References

phabricator.wikimedia.org/T387691

gerrit.wikimedia.org/...a8cfeab0d4457417773fa884e271968e5657

cve.org (CVE-2025-32069)

nvd.nist.gov (CVE-2025-32069)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-32069

Support options

Helpdesk Chat, Email, Knowledgebase