Cross-Site Scripting Vulnerability in MediaWiki EmbedVideo Extension
CVE-2026-55690

7.5HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-55690?

The EmbedVideo Extension for MediaWiki allows users to embed video clips from various sharing services. A vulnerability exists in versions prior to 4.1.0, where the EmbedServiceFactory interpolates a user-controlled service name into exception messages. This can lead to an attacker injecting malicious HTML or JavaScript through error outputs, which executes in the context of the wiki for users who view the page. The issue has been addressed in version 4.1.0 with appropriate security measures.

Affected Version(s)

mediawiki-extensions-EmbedVideo < 4.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.