Cross-Site Scripting Vulnerability in Mediawiki GrowthExperiments Extension
CVE-2026-22713
2.3LOW
What is CVE-2026-22713?
The vulnerability in the Mediawiki GrowthExperiments Extension is caused by improper neutralization of user input during web page generation, allowing attackers to execute malicious scripts in the context of the user's browser. This can lead to unauthorized actions and data exposure, impacting user trust and security. Versions 1.39 through 1.45 are confirmed to be affected, highlighting the need for prompt updates to mitigate these risks.
Affected Version(s)
Mediawiki - GrowthExperiments Extension 1.45
Mediawiki - GrowthExperiments Extension 1.44
Mediawiki - GrowthExperiments Extension 1.43
