Reflected XSS Vulnerability in Wikimedia Foundation’s MediaWiki ReadingLists Extension
CVE-2026-103437

1.1LOW

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-103437?

A reflected XSS vulnerability exists in the MediaWiki ReadingLists extension developed by Wikimedia Foundation. This vulnerability stems from improper neutralization of script-related HTML tags in web pages, allowing attackers to execute malicious scripts in the context of a user's browser. Users accessing compromised links may inadvertently pass sensitive information to the attacker, leading to potential security breaches. The affected versions include 1.45 and 1.46, highlighting the importance of timely updates to safeguard against such vulnerabilities.

Affected Version(s)

MediaWiki ReadingLists extension 1.46

MediaWiki ReadingLists extension 1.45

References

CVSS V4

Score:
1.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
.