Cross-site Scripting Vulnerability in Wikimedia Foundation's MediaWiki
CVE-2025-67475
NONE
What is CVE-2025-67475?
An improper neutralization of input during web page generation vulnerability exists in Wikimedia Foundation's MediaWiki. This flaw may allow attackers to exploit user input fields, leading to potential unauthorized access and control over user sessions. Affected versions include those earlier than 1.39.16, along with 1.43.6, 1.44.3, and 1.45.1. It is critical for users to update their installations to mitigate risks associated with this vulnerability.
Affected Version(s)
MediaWiki * < 1.39.16, 1.43.6, 1.44.3, 1.45.1
