PT-2025-16012 · Mediawiki+3 · Mediawiki+3

Published

2025-02-24

·

Updated

2025-11-05

·

CVE-2025-32699

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: MediaWiki versions prior to 1.39.12 MediaWiki versions prior to 1.42.6 MediaWiki versions prior to 1.43.1 Parsoid versions prior to 0.16.5 Parsoid versions prior to 0.19.2 Parsoid versions prior to 0.20.2
Description: The issue affects the MediaWiki and Parsoid software. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations: For MediaWiki versions prior to 1.39.12, update to version 1.39.12 or later. For MediaWiki versions prior to 1.42.6, update to version 1.42.6 or later. For MediaWiki versions prior to 1.43.1, update to version 1.43.1 or later. For Parsoid versions prior to 0.16.5, update to version 0.16.5 or later. For Parsoid versions prior to 0.19.2, update to version 0.19.2 or later. For Parsoid versions prior to 0.20.2, update to version 0.20.2 or later.

Fix

Special Elements Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06070
BIT-MEDIAWIKI-2025-32699
CVE-2025-32699
DLA-4249-1
DSA-5901-1
MGASA-2025-0260

Affected Products

Debian
Mediawiki
Parsoid
Red Os