Mediawiki · Cargo Extension · CVE-2026-39841
Name of the Vulnerable Software and Affected Versions
Mediawiki - Cargo Extension versions prior to 3.8.7
Description
A flaw exists in the Mediawiki - Cargo Extension that allows for Stored Cross-Site Scripting (XSS). This is due to improper neutralization of script-related HTML tags within a web page. The issue allows an attacker to inject malicious scripts into the application, potentially compromising user accounts or data.
Recommendations
Update Mediawiki - Cargo Extension to version 3.8.7 or later.