Cross-Site Scripting Vulnerability in MediaWiki FlexDiagrams Extension by Wikimedia Foundation
CVE-2025-62670

6.9MEDIUM

What is CVE-2025-62670?

The MediaWiki FlexDiagrams Extension, developed by Wikimedia Foundation, is susceptible to a vulnerability that allows stored Cross-Site Scripting (XSS) attacks due to improper neutralization of input during web page generation. An attacker exploiting this flaw can inject malicious scripts into web pages viewed by other users, potentially compromising their data and sessions. This vulnerability highlights the importance of input sanitation to maintain robust web application security.

Affected Version(s)

Mediawiki - FlexDiagrams Extension master

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
.
CVE-2025-62670 : Cross-Site Scripting Vulnerability in MediaWiki FlexDiagrams Extension by Wikimedia Foundation