Cross-Site Scripting Vulnerability in Wikimedia Foundation Mediawiki - FlaggedRevs Extension
CVE-2025-53491
Currently unrated
What is CVE-2025-53491?
The Mediawiki - FlaggedRevs Extension from Wikimedia Foundation contains a vulnerability that allows for Cross-Site Scripting (XSS). This occurs due to improper neutralization of input during web page generation, which could allow attackers to inject malicious scripts into web pages viewed by other users. The issue affects all versions of the FlaggedRevs Extension prior to 1.43.2, making it critical for users to upgrade to the latest version to mitigate potential exploitation risks.
Affected Version(s)
Mediawiki - FlaggedRevs Extension 1.43.x < 1.43.2