Cross-Site Scripting Vulnerability in Mediawiki GrowthExperiments Extension
CVE-2026-22713

2.3LOW

What is CVE-2026-22713?

The vulnerability in the Mediawiki GrowthExperiments Extension is caused by improper neutralization of user input during web page generation, allowing attackers to execute malicious scripts in the context of the user's browser. This can lead to unauthorized actions and data exposure, impacting user trust and security. Versions 1.39 through 1.45 are confirmed to be affected, highlighting the need for prompt updates to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Mediawiki - GrowthExperiments Extension 1.45

Mediawiki - GrowthExperiments Extension 1.44

Mediawiki - GrowthExperiments Extension 1.43

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
SomeRandomDeveloper
.