PT-2026-24147 · Mediawiki · Kbucket
Kcnotes
·
Published
2026-03-09
·
Updated
2026-03-10
·
CVE-2026-30917
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Bucket versions prior to 2.1.1
Description
Bucket is a MediaWiki extension used to store and retrieve structured data on articles. A stored cross-site scripting (XSS) issue exists that allows malicious code to be inserted into any Bucket table field with a PAGE type. This code will execute when a user views the corresponding Bucket namespace page.
Recommendations
Update to Bucket version 2.1.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kbucket