Cross-Site Scripting Vulnerability in Wikimedia Foundation's Mediawiki MintyDocs Extension
CVE-2025-53492
What is CVE-2025-53492?
The Mediawiki - MintyDocs Extension from the Wikimedia Foundation is vulnerable to an improper neutralization of input, allowing for persistent cross-site scripting (XSS) attacks. This arises when user inputs are not properly sanitized during the web page generation process. Attackers could exploit this flaw in affected versions (1.39.X, 1.42.X, and versions from 1.43.X up to 1.43.1) to inject malicious scripts, possibly compromising user data and session cookies. Timely updates to version 1.43.2 are recommended to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mediawiki - MintyDocs Extension 1.43.x < 1.43.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
