PT-2025-25346 · Mediawiki · Mediawiki Citizen Skin

Somemwdev

·

Published

2025-06-12

·

Updated

2025-08-22

·

CVE-2025-49576

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki Citizen Skin versions prior to 3.3.1
Description The issue concerns the Citizen MediaWiki skin, which allows extensions to be part of a cohesive experience. Specifically, the citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML. This allows anyone who can edit these messages to insert arbitrary HTML into the DOM, potentially leading to HTML injection.
Recommendations For versions prior to 3.3.1, update to version 3.3.1 to resolve the issue. As a temporary workaround, consider restricting access to editing the citizen-search-noresults-title and citizen-search-noresults-desc system messages until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-49576
GHSA-86XF-2MGP-GV3G

Affected Products

Mediawiki Citizen Skin