Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS.

This issue affects MediaWiki WikiForum extension: master.
Published: 2026-09-30
Score: 1.1 Low
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of script‑related HTML tags, enabling stored Cross‑Site Scripting in system messages on the MediaWiki WikiForum extension. Because the payload is persisted, an attacker who can write messages can embed arbitrary script that will be executed in the browsers of all users who view those messages. The injected code could read cookies, session tokens, or perform actions on behalf of the victim, leading to loss of confidentiality, integrity, and possibly account compromise. The weakness is identified as CWE‑80.

Affected Systems

The flaw affects the MediaWiki WikiForum extension, specifically the master branch where the issue was discovered. Users running this extension without the patch are vulnerable. The product is maintained by the Wikimedia Foundation. No explicit version numbers are supplied, so the risk applies to all instances that have not yet incorporated the latest build where the fix is present.

Risk and Exploitability

The CVSS score is 1.1, indicating a very low severity under standard scoring. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation is unlikely at present. However, because the attack vector is likely remote – any authenticated or possibly unauthenticated user could create messages – the risk may increase if the platform is exposed to a broader audience. Administrators should nevertheless address the issue promptly to eliminate the potential for XSS abuse.

Generated by OpenCVE AI on September 30, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MediaWiki WikiForum extension to the latest version from the Wikimedia Foundation that contains the XSS fix.
  • If the extension is required but cannot be updated immediately, disable or remove the system messages feature that allows storing user‑supplied HTML.
  • As a temporary measure, apply input sanitization to strip script‑related tags from messages, thereby mitigating the injection vector and addressing the CWE‑80 flaw.

Generated by OpenCVE AI on September 30, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki WikiForum extension: master.
Title Stored XSS through system messages in WikiForum
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-30T16:23:56.008Z

Reserved: 2026-09-30T15:41:01.270Z

Link: CVE-2026-103444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T17:16:43.177

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-103444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)