Cross-Site Scripting Vulnerability in MediaWiki Wikistories by Wikimedia Foundation
CVE-2026-103438

0.3LOW

What is CVE-2026-103438?

The Wikimedia Foundation's MediaWiki Wikistories extension contains a vulnerability that arises from improper handling of Script-Related HTML tags in web pages. This flaw enables potential attackers to execute arbitrary JavaScript within the context of the user’s browser. Users accessing affected versions of the extension (1.46, 1.45, and 1.43) could be tricked into executing malicious scripts, jeopardizing their data and session integrity. It is crucial for users and administrators to apply security best practices and monitor for updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

MediaWiki Wikistories extension 1.46

MediaWiki Wikistories extension 1.45

MediaWiki Wikistories extension 1.43

References

CVSS V4

Score:
0.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.