Cross-Site Scripting Vulnerability in Mediawiki Cargo Extension
CVE-2026-96875

6.9MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-96875?

A cross-site scripting vulnerability has been identified in the Cargo extension of Mediawiki, allowing for stored XSS attacks. This vulnerability stems from improper handling of user input during the web page generation process, which may permit an attacker to execute arbitrary scripts in the context of other users' sessions. This could lead to unauthorized actions or the exposure of sensitive information. Users are advised to update to secure versions and apply necessary patches to mitigate the risk.

Affected Version(s)

Mediawiki - Cargo extension 0 <= 3.9.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bombobombone - https://bombobombone.github.io
.