XSS Vulnerability in MediaWiki Wikbase Extension by Wikimedia Foundation
CVE-2026-103439
0.3LOW
What is CVE-2026-103439?
The MediaWiki Wikbase extension, developed by the Wikimedia Foundation, contains an XSS vulnerability due to improper handling of Script-Related HTML tags in user-input web pages. This flaw can be exploited by attackers to inject malicious scripts, potentially compromising user sessions and defacing web content. Affected versions include 1.46, 1.45, and 1.43, which are susceptible to these script injection attacks, emphasizing the importance of timely updates and security patches.
Affected Version(s)
MediaWiki Wikbase extension 1.46
MediaWiki Wikbase extension 1.45
MediaWiki Wikbase extension 1.43
