Cross-Site Scripting Vulnerability in Wikimedia Foundation's Mediawiki MintyDocs Extension
CVE-2025-53492

3.7LOW

What is CVE-2025-53492?

The Mediawiki - MintyDocs Extension from the Wikimedia Foundation is vulnerable to an improper neutralization of input, allowing for persistent cross-site scripting (XSS) attacks. This arises when user inputs are not properly sanitized during the web page generation process. Attackers could exploit this flaw in affected versions (1.39.X, 1.42.X, and versions from 1.43.X up to 1.43.1) to inject malicious scripts, possibly compromising user data and session cookies. Timely updates to version 1.43.2 are recommended to mitigate this risk.

Affected Version(s)

Mediawiki - MintyDocs Extension 1.39.x

Mediawiki - MintyDocs Extension 1.42.x

Mediawiki - MintyDocs Extension 1.43.x < 1.43.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
.
CVE-2025-53492 : Cross-Site Scripting Vulnerability in Wikimedia Foundation's Mediawiki MintyDocs Extension