Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS).

This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43.
Published: 2026-09-30
Score: 0.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Client‑Side Script Execution (XSS)
Action: Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of Script‑Related HTML tags in MediaWiki Wikistories extension, enabling basic client‑side XSS. An attacker who can insert content processed by rawParams() and escaped() may cause arbitrary JavaScript to execute in the victim’s browser when a page is rendered.

Affected Systems

Affected products are the MediaWiki Wikistories extension released by The Wikimedia Foundation. Versions 1.46, 1.45, and 1.43 are impacted and are available as part of standard MediaWiki deployments.

Risk and Exploitability

The CVSS score of 0.3 indicates low severity. No EPSS score is available. The vulnerability is not listed in the CISA KEV catalog, implying no observed large‑scale exploitation. Because XSS is typically injected through a web page, the likely attack vector is through a user accessing content that contains unescaped data from the Wikistories extension, such as a story title or comment.

Generated by OpenCVE AI on September 30, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Wikistories extension to a patched release; apply the commit Iad1281879723eba73e4338a00d5ff35c6eed0c3e or a later version that includes the fix.
  • Ensure that all data rendered by the extension is correctly escaped and that no rawParams() output reaches the browser without proper sanitization.
  • Deploy a content‑security‑policy header that blocks inline scripts, such as default-src 'self'; script-src 'self'; and object-src 'none', to reduce impact if XSS still occurs.

Generated by OpenCVE AI on September 30, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43.
Title Various rawParams() and escaped() updates to prevent XSS in Wikistories extension
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 0.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-30T20:01:01.753Z

Reserved: 2026-09-30T15:41:01.269Z

Link: CVE-2026-103438

cve-icon Vulnrichment

Updated: 2026-09-30T18:47:04.964Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T18:18:16.440

Modified: 2026-09-30T21:17:08.710

Link: CVE-2026-103438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:30:18Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)