PT-2025-27833 · Mediawiki · Shortdescription+1

CVE-2025-53369

·

Published

2025-07-03

·

Updated

2025-07-03

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: MediaWiki extension Short Description versions 4.0.0
Description: The issue arises from the lack of proper sanitization of short descriptions before they are inserted as HTML, allowing any user to insert arbitrary HTML into the DOM by editing a page. This can lead to HTML injection.
Recommendations: For version 4.0.0, update to version 4.0.1 to patch this security flaw. As a temporary workaround, consider restricting the ability to edit pages until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53369
GHSA-P85Q-MWW9-GWQF

Affected Products

Mediawiki
Shortdescription