PT-2025-27831 · Unknown+1 · Shortdescription Extension+1

Somemwdev

·

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-53370

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Citizen MediaWiki skin versions 1.9.4 through 3.4.0
Description: The Citizen MediaWiki skin has an issue where short descriptions set via the ShortDescription extension are inserted as raw HTML, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 3.4.0.
Recommendations: For versions 1.9.4 through 3.4.0, update to version 3.4.0 to patch this issue. As a temporary workaround, consider restricting the use of the ShortDescription extension until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-53370
GHSA-PRMV-7R8C-794G

Affected Products

Mediawiki Citizen Skin
Shortdescription Extension