Cross-Site Scripting Vulnerability in MediaWiki Wikistories by Wikimedia Foundation
CVE-2026-103438
0.3LOW
What is CVE-2026-103438?
The Wikimedia Foundation's MediaWiki Wikistories extension contains a vulnerability that arises from improper handling of Script-Related HTML tags in web pages. This flaw enables potential attackers to execute arbitrary JavaScript within the context of the user’s browser. Users accessing affected versions of the extension (1.46, 1.45, and 1.43) could be tricked into executing malicious scripts, jeopardizing their data and session integrity. It is crucial for users and administrators to apply security best practices and monitor for updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
MediaWiki Wikistories extension 1.46
MediaWiki Wikistories extension 1.45
MediaWiki Wikistories extension 1.43
