Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS.

This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from an improper neutralization of input in the Wikibase extension, allowing attackers to embed malicious JavaScript into a system message that is not escaped when rendered. The stored payload executes in the browsers of any user who views the message, enabling session hijacking, defacement, or malware delivery. The weakness is identified as CWE-79.

Affected Systems

Affected are releases of the Wikimedia Foundation MediaWiki Wikibase Extension recorded as before 1.46.1, 1.45.5, and 1.43.10. Any site running those versions is susceptible, regardless of the Wikimedia project.

Risk and Exploitability

No official CVSS score is published and EPSS is unavailable, but the exploitability is high because the payload persists in the database. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploitation yet. Attackers can leverage available editing rights or credentials to inject the malicious system message, after which any visitor will execute the script automatically.

Generated by OpenCVE AI on September 30, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Wikibase extension to a non‑affected release (≥1.46.1, ≥1.45.5, or ≥1.43.10 depending on your setup).
  • Examine all existing system messages for embedded scripting tags or suspicious content and purge or neutralize them.
  • Confirm that system messages are rendered with the extension’s default escaping logic, or apply an additional output filter to escape any user‑supplied data if custom rendering is in use.

Generated by OpenCVE AI on September 30, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10.
Title Stored XSS on Wikibase Special:SetSiteLink via unescaped system message
Weaknesses CWE-79
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-29T16:52:54.809Z

Reserved: 2026-09-25T16:03:15.841Z

Link: CVE-2026-100245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T17:17:01.567

Modified: 2026-09-29T21:35:07.960

Link: CVE-2026-100245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')