PT-2025-16142 · Mediawiki · Mediawiki

Blankeclair

·

Published

2025-04-11

·

Updated

2025-04-11

·

CVE-2025-32078

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions: Mediawiki - Version Compare Extension versions 1.39 through 1.43
Description: The issue is related to Improper Encoding or Escaping of Output, which allows Cross-Site Scripting (XSS) in the Mediawiki - Version Compare Extension.
Recommendations: For versions 1.39 through 1.43, update to a version that fixes the Improper Encoding or Escaping of Output issue to prevent Cross-Site Scripting (XSS). At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2025-32078

Affected Products

Mediawiki