Cross-Site Scripting Vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension
CVE-2026-103047
Currently unrated
What is CVE-2026-103047?
The Mediawiki - CentralAuth extension developed by the Wikimedia Foundation has a vulnerability that allows for stored cross-site scripting (XSS) attacks due to improper handling of user inputs while generating web pages. This flaw can be exploited to inject malicious scripts, which can execute in users' browsers, potentially leading to unauthorized actions, data theft, or account compromise. It is essential for users of the affected versions to update to the latest release to mitigate this risk. For detailed tracking and mitigation, refer to the provided resources.
Affected Version(s)
Mediawiki - CentralAuth extension 0 < 1.46.1, 1.45.5, 1.43.10
