Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements.

This issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.
Published: 2026-09-30
Score: 1.1 Low
EPSS: n/a
KEV: No
Impact: Cross-site scripting (XSS)
Action: Assess Impact
AI Analysis

Impact

The MediaWiki Collection (Book) extension contains a basic cross‑site scripting flaw caused by improper neutralization of script‑related HTML tags. Attackers can send malicious input through API endpoints that create session‑seeded javascript URLs, leading to the injection of executable scripts into pages viewed by other users. This could allow attackers to execute arbitrary JavaScript in the victim’s browser, potentially compromising session cookies, hijacking accounts, or performing phishing attacks. The flaw is classified as CWE‑80.

Affected Systems

Affected by versions 1.46, 1.45, and 1.43 of the MediaWiki Collection (Book) extension from The Wikimedia Foundation. Any installation deploying those versions is susceptible until updated.

Risk and Exploitability

The CVSS score is 1.1, indicating a very low severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires the attacker to craft a malicious API request; no publicly documented exploits exist. Nevertheless, the low score should not discourage remedial action, because any XSS could be used for framing or credential theft depending on context.

Generated by OpenCVE AI on September 30, 2026 at 17:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MediaWiki Collection (Book) extension to the latest version that resolves the XSS issue.
  • If the extension is not essential, remove or disable it to eliminate the vulnerability.
  • Ensure that API endpoints validate input and escape output to prevent script injection.

Generated by OpenCVE AI on September 30, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements. This issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.
Title API permits session-seeded javascript URL XSS
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-30T16:19:16.720Z

Reserved: 2026-09-30T15:41:01.270Z

Link: CVE-2026-103443

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T17:16:43.030

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-103443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)