Description
Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
Published: 2026-04-07
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

A vulnerability in the WikiLove extension of MediaWiki allows an attacker to inject malicious script that is stored and later displayed to users. The improper neutralization of alternate XSS syntax means that crafted input can persist and be executed in the context of a victim’s browser, potentially enabling session hijacking, defacement, or phishing. This weakness corresponds to CWE‑87 and supports a cross‑site scripting attack with a high exploit potential.

Affected Systems

The flaw affects installations of the Wikimedia Foundation's MediaWiki that use the WikiLove extension before version 1.43 or before the patch was applied to the master branch. The issue has been fixed in the release branches for MediaWiki 1.43, 1.44, and 1.45, so systems running these or later versions are no longer vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 6.9 indicates a medium severity. The EPSS score of less than 1% suggests a low probability of seeing an exploit in the wild at this time, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw is a stored XSS, an attacker only needs to be able to add a system message or otherwise contribute content to the extension; no additional prerequisites are noted. The lack of a public exploit does not negate the risk: any authenticated or even publicly available message could be used, so the vulnerability can be leveraged remotely by users with write access to WikiLove messages.

Generated by OpenCVE AI on April 8, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MediaWiki to version 1.43 or newer, ensuring the latest WikiLove extension is in use.
  • If upgrading is not immediately possible, replace the WikiLove extension with the patched commit from the master branch, or apply the patch that neutralizes alternate XSS syntax.
  • Verify that the replacement or upgraded installation processes the stored messages correctly before allowing them to be displayed to end users.

Generated by OpenCVE AI on April 8, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Wikimedia
Wikimedia mediawiki-wikilove Extension
Vendors & Products Wikimedia
Wikimedia mediawiki-wikilove Extension

Wed, 08 Apr 2026 22:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikilove Extension: 1.43.7, 1.44.4, 1.45.2. Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.

Tue, 07 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikilove Extension: 1.43.7, 1.44.4, 1.45.2.
Title Stored XSS through system messages in WikiLove
Weaknesses CWE-87
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Wikimedia Mediawiki-wikilove Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-04-08T22:02:16.476Z

Reserved: 2026-01-08T23:23:42.385Z

Link: CVE-2026-22711

cve-icon Vulnrichment

Updated: 2026-04-07T20:40:36.379Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-07T19:16:43.980

Modified: 2026-04-08T23:16:58.240

Link: CVE-2026-22711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:28:43Z

Weaknesses