Cross-Site Scripting Vulnerability in MediaWiki BlueSky Skin
CVE-2025-62665
6.9MEDIUM
What is CVE-2025-62665?
An improper neutralization of input during web page generation vulnerability in the BlueSky skin of MediaWiki allows attackers to inject malicious scripts. This results in stored XSS, enabling execution of arbitrary JavaScript in the context of authenticated users. The vulnerability is present in versions prior to 1.39, posing a risk to systems using this skin within their MediaWiki installations.
Affected Version(s)
Mediawiki - Skin:BlueSky master < 1.39