Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS.

This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.
Published: 2026-09-30
Score: 1.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Basic Reflected Cross‑Site Scripting via JavaScript URL in imported metadata
Action: Update Extension
AI Analysis

Impact

The ReadingLists extension fails to neutralize script‑related HTML tags in imported metadata, allowing an attacker to embed a JavaScript URL that will execute in the victim’s browser when the metadata is viewed. The malicious code runs with the user’s privileges, potentially hijacking sessions or redirecting to malicious sites. This is a basic reflected XSS vulnerability, meaning the attacker simply needs to craft a URL containing the malicious metadata and get a user to open it. The description explicitly states the flaw is a Reflected XSS due to improper neutralization of script tags.

Affected Systems

The flaw is present in MediaWiki ReadingLists extension versions 1.46 and 1.45 as used by The Wikimedia Foundation. All installations using those extension versions remain vulnerable until the extension is upgraded to a fixed release.

Risk and Exploitability

The CVSS score of 1.1 indicates a low overall severity. No EPSS data is available, so the precise exploitation probability is unknown; however, based on the description, the vulnerability requires user interaction to trigger the reflected XSS, which suggests widespread automated exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalogue, further indicating limited exposure at present.

Generated by OpenCVE AI on September 30, 2026 at 20:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MediaWiki ReadingLists extension to a version that includes the XSS fix (e.g., 1.47 or later).
  • Sanitize and validate all imported metadata, ensuring that URLs are not allowed to use the javascript: scheme and that script tags are removed.
  • Implement a Content‑Security‑Policy that blocks inline scripting and disallows the javascript: scheme to mitigate similar XSS risks in the future.

Generated by OpenCVE AI on September 30, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.
Title ReadingLists imported metadata permits JavaScript URL XSS
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-30T20:01:02.016Z

Reserved: 2026-09-30T15:41:01.269Z

Link: CVE-2026-103437

cve-icon Vulnrichment

Updated: 2026-09-30T18:47:05.633Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T18:18:16.290

Modified: 2026-09-30T21:17:08.583

Link: CVE-2026-103437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:30:18Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)