Reflected XSS Vulnerability in Wikimedia Foundation’s MediaWiki ReadingLists Extension
CVE-2026-103437
1.1LOW
What is CVE-2026-103437?
A reflected XSS vulnerability exists in the MediaWiki ReadingLists extension developed by Wikimedia Foundation. This vulnerability stems from improper neutralization of script-related HTML tags in web pages, allowing attackers to execute malicious scripts in the context of a user's browser. Users accessing compromised links may inadvertently pass sensitive information to the attacker, leading to potential security breaches. The affected versions include 1.45 and 1.46, highlighting the importance of timely updates to safeguard against such vulnerabilities.
Affected Version(s)
MediaWiki ReadingLists extension 1.46
MediaWiki ReadingLists extension 1.45
