Cross-Site Scripting Vulnerability in Wikimedia Foundation MediaWiki - WikiLambda Extension
CVE-2026-103046
Currently unrated
What is CVE-2026-103046?
A vulnerability in the Wikimedia Foundation's MediaWiki - WikiLambda extension has been identified, allowing for the potential execution of malicious scripts. This issue arises from improper handling of user input during web page generation, leading to stored cross-site scripting (XSS) vulnerabilities. When users are able to input data that is insufficiently sanitized, attackers may exploit this flaw to inject scripts that can be executed in the browsers of users who access the affected pages. To mitigate risks associated with this vulnerability, it is crucial for users to upgrade to version 1.46.1 or later, where this issue has been addressed.
Affected Version(s)
Mediawiki - WikiLambda Extension 0 < 1.46.1
