Home

Description

Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.

PUBLISHED Reserved 2025-04-09 | Published 2025-04-10 | Updated 2025-11-03 | Assigner wikimedia-foundation




LOW: 2.1CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/RE:M/U:Amber

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Product status

Default status
unaffected

Any version before 1.39.12, 1.42.6, 1.43.1
affected

Default status
unaffected

Any version before 0.16.5, 0.19.2, 0.20.2
affected

References

lists.debian.org/debian-lts-announce/2025/07/msg00012.html

phabricator.wikimedia.org/T387130

cve.org (CVE-2025-32699)

nvd.nist.gov (CVE-2025-32699)

Download JSON