Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GrowthExperiments Extension: 1.45, 1.44, 1.43, 1.39.
Published: 2026-01-09
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting (XSS) via unsanitized edit summaries in the GrowthExperiments extension
Action: Patch
AI Analysis

Impact

This vulnerability allows an attacker to inject malicious scripts into edit summary fields, which are rendered on subsequent pages. The flaw is an improper neutralization of input during web page generation and falls under the classic input‑validation weakness. Successful exploitation could let the attacker execute arbitrary client‑side code in the context of victims who view edited pages, undermining confidentiality and potentially enabling session hijacking or phishing.

Affected Systems

The flaw affects the Wikimedia Foundation’s MediaWiki GrowthExperiments extension in versions 1.39, 1.43, 1.44 and 1.45. These are used on Wikimedia sites that enable the GrowthExperiments feature, such as the main English Wikipedia and other Wikimedia projects that run the same extension stack.

Risk and Exploitability

The CVSS base score is 2.3, and the EPSS score is less than 1 %, indicating the vulnerability is considered low severity and has a low probability of being exploited in the wild. It is currently not listed in CISA’s KEV catalog. The attack vector is inferred to be via a crafted edit summary that an authenticated editor submits; the vulnerability does not require elevated privileges beyond the standard editing or writing permissions. Because the exploit requires user interaction on the page that contains the edit summary, the risk remains limited to users who view such pages.

Generated by OpenCVE AI on April 18, 2026 at 07:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GrowthExperiments extension to the latest available version that addresses the XSS flaw.
  • Ensure that all edit summary input is properly encoded or sanitized before inclusion in rendered pages, following the principles of CWE-79 to avoid script injection.
  • Restrict edit‑summary editing privileges to trusted users and consider limiting allowed characters or implementing additional input validation if an immediate upgrade is not possible.

Generated by OpenCVE AI on April 18, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 12 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Growth
Growth growthexperiments
CPEs cpe:2.3:a:growth:growthexperiments:1.39:*:*:*:*:mediawiki:*:*
cpe:2.3:a:growth:growthexperiments:1.43:*:*:*:*:mediawiki:*:*
cpe:2.3:a:growth:growthexperiments:1.44:*:*:*:*:mediawiki:*:*
cpe:2.3:a:growth:growthexperiments:1.45:*:*:*:*:mediawiki:*:*
Vendors & Products Growth
Growth growthexperiments
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Fri, 09 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediawiki
Mediawiki mediawiki
Wikimedia
Wikimedia mediawiki-growthexperiments Extension
Vendors & Products Mediawiki
Mediawiki mediawiki
Wikimedia
Wikimedia mediawiki-growthexperiments Extension

Fri, 09 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GrowthExperiments Extension: 1.45, 1.44, 1.43, 1.39.
Title Stored XSS through edit summaries in GrowthExperiments
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Growth Growthexperiments
Mediawiki Mediawiki
Wikimedia Mediawiki-growthexperiments Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-01-09T19:17:27.530Z

Reserved: 2026-01-08T23:23:42.385Z

Link: CVE-2026-22713

cve-icon Vulnrichment

Updated: 2026-01-09T19:17:23.517Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-09T00:15:46.000

Modified: 2026-02-12T17:47:31.803

Link: CVE-2026-22713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T07:30:36Z

Weaknesses