Stored XSS Vulnerability in MediaWiki WikiForum Extension by Wikimedia Foundation
CVE-2026-103444

1.1LOW

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-103444?

A security flaw in the MediaWiki WikiForum extension by Wikimedia Foundation permits the improper neutralization of script-related HTML tags, leading to Stored XSS vulnerabilities. This issue allows attackers to inject malicious scripts into web pages, which can then be executed in the context of users accessing the forum. Vigilance is essential to safeguard user data and maintain the integrity of the web application. Immediate action is recommended to apply patches and prevent exploitation.

Affected Version(s)

MediaWiki WikiForum extension master

References

CVSS V4

Score:
1.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
.