Home
LOW: 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/RE:M/U:AmberDefault status
unaffected
Any version before 1.39.12, 1.42.6, 1.43.1
affected
Default status
unaffected
Any version before 0.16.5, 0.19.2, 0.20.2
affected
Description
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 1.39.12, 1.42.6, 1.43.1
Any version before 0.16.5, 0.19.2, 0.20.2
References
lists.debian.org/debian-lts-announce/2025/07/msg00012.html
phabricator.wikimedia.org/T387130