Cross-Site Scripting Vulnerability in The Wikimedia Foundation's CentralNotice Extension
CVE-2026-103051

Currently unrated

What is CVE-2026-103051?

A vulnerability in The Wikimedia Foundation's CentralNotice extension allows for the improper neutralization of user input, leading to potential stored cross-site scripting (XSS) attacks. This can enable malicious actors to inject harmful scripts into web pages, which might execute when users interact with compromised content. Affected versions include all prior to 1.46.1, as well as specific versions 1.45.5 and 1.43.10. Users of this extension should implement immediate mitigation measures to safeguard against potential exploitation.

Affected Version(s)

Mediawiki - CentralNotice extension 0 < 1.46.1, 1.45.5, 1.43.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
SomeRandomDeveloper
.