Cross-Site Scripting Vulnerability in MediaWiki BlueSky Skin
CVE-2025-62665

6.9MEDIUM

Key Information:

Vendor
CVE Published:
18 October 2025

What is CVE-2025-62665?

An improper neutralization of input during web page generation vulnerability in the BlueSky skin of MediaWiki allows attackers to inject malicious scripts. This results in stored XSS, enabling execution of arbitrary JavaScript in the context of authenticated users. The vulnerability is present in versions prior to 1.39, posing a risk to systems using this skin within their MediaWiki installations.

Affected Version(s)

Mediawiki - Skin:BlueSky master < 1.39

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
.
CVE-2025-62665 : Cross-Site Scripting Vulnerability in MediaWiki BlueSky Skin