PT-2025-27764 · Wikimedia Foundation+2 · Vector+1

Published

2025-07-02

·

Updated

2026-02-02

·

CVE-2025-6596

CVSS v4.0

0.0

None

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wikimedia Foundation Vector versions 1.40.0 through 1.42.6 Wikimedia Foundation Vector version 1.43.0 Wikimedia Foundation Vector version 1.43.1 Wikimedia Foundation Vector version 1.44.0
Description The software contains an Improper Neutralization of Input During Web Page Generation issue, also known as Cross-site Scripting (XSS). This issue is found in the program files resources/skins.Vector.Js/portlets.Js and resources/skins.Vector.Legacy.Js/portlets.Js.
Recommendations Update to Vector version 1.42.7 or later. Update to Vector version 1.43.2 or later. Update to Vector version 1.44.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-6596

Affected Products

Vector
Mediawiki