Cross-Site Scripting Vulnerability in Wikimedia MediaWiki - MassMessage Extension
CVE-2026-103050
Currently unrated
What is CVE-2026-103050?
A vulnerability in the MediaWiki MassMessage extension allows improper handling of user input, leading to a stored XSS risk. This flaw can enable attackers to inject malicious scripts into web pages viewed by other users. When exploited, the vulnerability can result in the unintended exposure of sensitive information and unauthorized actions performed on behalf of victims. Affected versions include those prior to 1.46.1, as well as 1.45.5 and 1.43.10.
Affected Version(s)
Mediawiki - MassMessage extension 0 < 1.46.1, 1.45.5, 1.43.10
