Reflected XSS Vulnerability in MediaWiki's CheckUser Extension
CVE-2025-53478
Currently unrated
What is CVE-2025-53478?
The CheckUser extension for MediaWiki contains a reflected XSS vulnerability within the Special:Investigate interface. This flaw arises from improper escaping of internationalized system messages displayed in the 'IPs and User agents' tab, potentially allowing attackers to inject malicious scripts that could execute within the user’s browser. Users and administrators should upgrade to the latest versions to mitigate this risk.
Affected Version(s)
Mediawiki - CheckUser extension 1.39.x < 1.39.13
Mediawiki - CheckUser extension 1.42.x < 1.42.7
Mediawiki - CheckUser extension 1.43.x < 1.43.2