Cross-site Scripting Vulnerability in Wikimedia Foundation's Mediawiki - WikiLambda Extension
CVE-2025-62695
6.9MEDIUM
What is CVE-2025-62695?
A Cross-site Scripting (XSS) vulnerability has been identified in the Mediawiki - WikiLambda Extension developed by the Wikimedia Foundation. This vulnerability arises from improper neutralization of user input during web page generation, which can lead to stored XSS attacks. When exploited, this flaw allows attackers to inject malicious scripts that could be executed in the context of a user’s session, posing significant security risks. As a result, sensitive user data could be compromised, and the integrity of the affected websites may be jeopardized.
Affected Version(s)
Mediawiki - WikiLambda Extension master