Cross-Site Scripting Vulnerability in Wikimedia Foundation Mediawiki - FlaggedRevs Extension
CVE-2025-53491

Currently unrated

What is CVE-2025-53491?

The Mediawiki - FlaggedRevs Extension from Wikimedia Foundation contains a vulnerability that allows for Cross-Site Scripting (XSS). This occurs due to improper neutralization of input during web page generation, which could allow attackers to inject malicious scripts into web pages viewed by other users. The issue affects all versions of the FlaggedRevs Extension prior to 1.43.2, making it critical for users to upgrade to the latest version to mitigate potential exploitation risks.

Affected Version(s)

Mediawiki - FlaggedRevs Extension 1.43.x < 1.43.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dreamy_Jazz
.
CVE-2025-53491 : Cross-Site Scripting Vulnerability in Wikimedia Foundation Mediawiki - FlaggedRevs Extension