Improper Input Validation in Mediawiki AJAX Poll Extension by Wikimedia Foundation
CVE-2025-32070
10CRITICAL
What is CVE-2025-32070?
An improper input validation flaw in the AJAX Poll Extension of Mediawiki allows for Cross-Site Scripting (XSS) attacks. This vulnerability can be exploited by attackers to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions and data exposure. It affects versions 1.39 to 1.43, emphasizing the necessity for users to update to the latest release to mitigate any associated risks.
Affected Version(s)
Mediawiki - AJAX Poll Extension 1.39 <= 1.43
