Cross-Site Scripting Vulnerability in The Wikimedia Foundation's CentralNotice Extension
CVE-2026-103051
Currently unrated
What is CVE-2026-103051?
A vulnerability in The Wikimedia Foundation's CentralNotice extension allows for the improper neutralization of user input, leading to potential stored cross-site scripting (XSS) attacks. This can enable malicious actors to inject harmful scripts into web pages, which might execute when users interact with compromised content. Affected versions include all prior to 1.46.1, as well as specific versions 1.45.5 and 1.43.10. Users of this extension should implement immediate mitigation measures to safeguard against potential exploitation.
Affected Version(s)
Mediawiki - CentralNotice extension 0 < 1.46.1, 1.45.5, 1.43.10
