Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS).

This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.
Published: 2026-09-30
Score: 1.1 Low
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Monitor
AI Analysis

Impact

The CommonsMetadata extension for MediaWiki fails to neutralize script‑related HTML tags in the license URL field, allowing attacker‑controlled JavaScript to be delivered to a victim’s browser. This flaw is a basic cross‑site scripting (CWE‑80) weakness; the injected code runs with the privileges of the page viewer but does not provide direct access to the server or its data.

Affected Systems

MediaWiki CommonsMetadata extension versions 1.46, 1.45, and 1.43 from The Wikimedia Foundation are impacted. No other MediaWiki extensions or related software vendors are listed.

Risk and Exploitability

The CVSS score of 1.1 indicates very low severity, and no EPSS score is available, so the probability of exploitation is unknown. The flaw is not present in CISA’s KEV catalog. The likely attack vector requires a victim to view a page that includes an attacker‑controlled license URL; no elevated privileges or authentication are required. Although the overall risk is modest, this vulnerability remains a client‑side scripting risk for any user who can view affected media pages.

Generated by OpenCVE AI on October 1, 2026 at 00:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CommonsMetadata extension to the latest version that incorporates the XSS fix.
  • If an upgrade cannot be applied immediately, disable the license URL feature or remove the CommonsMetadata extension from public pages to block the injection surface.
  • Apply a strict URL–sanitization rule that strips script or event handler attributes from user‑supplied URLs to mitigate further input‑validation weaknesses.

Generated by OpenCVE AI on October 1, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.
Title attacker-controlled javascript license URL via XSS
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/R:U/V:C/RE:M/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-30T22:14:27.101Z

Reserved: 2026-09-30T22:09:46.952Z

Link: CVE-2026-103584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T23:16:57.737

Modified: 2026-09-30T23:16:57.737

Link: CVE-2026-103584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T01:00:10Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)