PT-2025-27830 · Mediawiki · Mediawiki Citizen Skin

Somemwdev

·

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-53368

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Citizen MediaWiki skin versions 1.9.4 through 3.4.0
Description: The Citizen MediaWiki skin has an issue where page descriptions are inserted into raw HTML without proper sanitization when using the old search bar. This allows any user with page editing privileges to insert cross-site scripting (XSS) payloads into the DOM for other users who are searching for specific pages.
Recommendations: For versions 1.9.4 through 3.4.0, update to version 3.4.0 to resolve the issue. As a temporary workaround, consider disabling the old search bar until a patch is available. Restrict access to page editing privileges to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-53368
GHSA-RQ6G-6G94-JFR4

Affected Products

Mediawiki Citizen Skin