Description
An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting leading to client‑side code execution
Action: Patch Immediately
AI Analysis

Impact

A Cross‑Site Scripting vulnerability exists in the MassMessage extension of MediaWiki for releases prior to 1.40.2. An attacker can trigger arbitrary JavaScript by crafting a URL such as Special:MassMessage?uselang=x‑xss, where the i18n key massmessage‑form‑page‑help is not properly sanitized. This flaw allows malicious code to run in the context of any user who views the affected page, potentially enabling credential theft, session hijacking, or defacement.

Affected Systems

All MediaWiki installations that employ the MassMessage extension before version 1.40.2 and allow the uselang parameter to be set via URLs are susceptible. Systems that use the extension in production environments and expose the Special:MassMessage interface without strict access controls are included.

Risk and Exploitability

The CVSS base score is 5.4, indicating a moderate impact. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is social engineering or a public link that directly targets the uselang parameter, with no authentication required. Exploitation requires only the ability to send or trick a user into visiting the crafted URL.

Generated by OpenCVE AI on September 15, 2026 at 16:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the MassMessage extension to version 1.40.2 or later
  • If an update is not immediately possible, escape or sanitize the massmessage‑form‑page‑help i18n output to neutralize any embedded script
  • Review and restrict the use of the uselang parameter in URLs to prevent direct manipulation and limit exposure of the MassMessage feature

Generated by OpenCVE AI on September 15, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediawiki
Mediawiki massmessage
Vendors & Products Mediawiki
Mediawiki massmessage

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title MassMessage Extension XSS via i18n Key

Mon, 14 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title MassMessage Extension Cross‑Site Scripting via i18n Key in MediaWiki

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title MassMessage Extension Cross‑Site Scripting via i18n Key in MediaWiki

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Mediawiki Massmessage
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:23:47.638Z

Reserved: 2024-01-12T00:00:00.000Z

Link: CVE-2024-23176

cve-icon Vulnrichment

Updated: 2026-09-14T15:23:23.028Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T07:17:16.097

Modified: 2026-09-28T14:10:00.213

Link: CVE-2024-23176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:51Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')