PT-2025-39387 · Mediawiki · Embedvideo Extension

Published

2025-09-24

·

Updated

2025-09-25

·

CVE-2025-59839

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions EmbedVideo Extension versions prior to 4.0.0
Description The EmbedVideo Extension for MediaWiki, which includes a parser function called #ev and parser tags for embedding video clips, contains a flaw. Versions 4.0.0 and earlier permit the addition of arbitrary attributes to an HTML element, potentially leading to stored cross-site scripting (XSS) through wikitext. The issue was addressed with commit 4e075d3.
Recommendations Update to EmbedVideo Extension version 4.0.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-59839
GHSA-4J5H-MVJ3-M48V

Affected Products

Embedvideo Extension