Reflected XSS Vulnerability in MediaWiki's CheckUser Extension
CVE-2025-53478
What is CVE-2025-53478?
The CheckUser extension for MediaWiki contains a reflected XSS vulnerability within the Special:Investigate interface. This flaw arises from improper escaping of internationalized system messages displayed in the 'IPs and User agents' tab, potentially allowing attackers to inject malicious scripts that could execute within the user’s browser. Users and administrators should upgrade to the latest versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mediawiki - CheckUser extension 1.39.x < 1.39.13
Mediawiki - CheckUser extension 1.42.x < 1.42.7
Mediawiki - CheckUser extension 1.43.x < 1.43.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
