Impact
The vulnerability is an improper neutralization of Script‑Related HTML tags in MediaWiki Wikistories extension, enabling basic client‑side XSS. An attacker who can insert content processed by rawParams() and escaped() may cause arbitrary JavaScript to execute in the victim’s browser when a page is rendered.
Affected Systems
Affected products are the MediaWiki Wikistories extension released by The Wikimedia Foundation. Versions 1.46, 1.45, and 1.43 are impacted and are available as part of standard MediaWiki deployments.
Risk and Exploitability
The CVSS score of 0.3 indicates low severity. No EPSS score is available. The vulnerability is not listed in the CISA KEV catalog, implying no observed large‑scale exploitation. Because XSS is typically injected through a web page, the likely attack vector is through a user accessing content that contains unescaped data from the Wikistories extension, such as a story title or comment.
OpenCVE Enrichment