Cross-Site Scripting Vulnerability in Wikimedia Foundation's Mediawiki MintyDocs Extension
CVE-2025-53492
3.7LOW
What is CVE-2025-53492?
The Mediawiki - MintyDocs Extension from the Wikimedia Foundation is vulnerable to an improper neutralization of input, allowing for persistent cross-site scripting (XSS) attacks. This arises when user inputs are not properly sanitized during the web page generation process. Attackers could exploit this flaw in affected versions (1.39.X, 1.42.X, and versions from 1.43.X up to 1.43.1) to inject malicious scripts, possibly compromising user data and session cookies. Timely updates to version 1.43.2 are recommended to mitigate this risk.
Affected Version(s)
Mediawiki - MintyDocs Extension 1.39.x
Mediawiki - MintyDocs Extension 1.42.x
Mediawiki - MintyDocs Extension 1.43.x < 1.43.2