Cross-Site Scripting Vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension
CVE-2026-100243
Currently unrated
What is CVE-2026-100243?
The Wikimedia Foundation's Mediawiki - WikiSEO Extension has a vulnerability that allows for Stored Cross-Site Scripting (XSS) due to improper neutralization of user input during the generation of web pages. This flaw can be exploited by an attacker to inject malicious scripts into the web application, potentially compromising user data and leading to unauthorized actions within a user session. Affected versions include those prior to 1.46.1, specifically 1.45.5 and 1.43.10. Users are advised to update to the latest version to mitigate this risk.
Affected Version(s)
Mediawiki - WikiSEO Extension * < 1.46.1, 1.45.5, 1.43.10
