Cross-Site Scripting Vulnerability in MediaWiki FlexDiagrams Extension by Wikimedia Foundation
CVE-2025-62670
6.9MEDIUM
What is CVE-2025-62670?
The MediaWiki FlexDiagrams Extension, developed by Wikimedia Foundation, is susceptible to a vulnerability that allows stored Cross-Site Scripting (XSS) attacks due to improper neutralization of input during web page generation. An attacker exploiting this flaw can inject malicious scripts into web pages viewed by other users, potentially compromising their data and sessions. This vulnerability highlights the importance of input sanitation to maintain robust web application security.
Affected Version(s)
Mediawiki - FlexDiagrams Extension master