Cross-Site Scripting Vulnerability in Wikimedia MediaWiki - MassMessage Extension
CVE-2026-103050

Currently unrated

What is CVE-2026-103050?

A vulnerability in the MediaWiki MassMessage extension allows improper handling of user input, leading to a stored XSS risk. This flaw can enable attackers to inject malicious scripts into web pages viewed by other users. When exploited, the vulnerability can result in the unintended exposure of sensitive information and unauthorized actions performed on behalf of victims. Affected versions include those prior to 1.46.1, as well as 1.45.5 and 1.43.10.

Affected Version(s)

Mediawiki - MassMessage extension 0 < 1.46.1, 1.45.5, 1.43.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
SomeRandomDeveloper
.