Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
Published: 2026-04-07
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in the MediaWiki Score extension, caused by the use of non‑reserved data attributes that are not properly escaped when generating web pages. Because the input is stored and later rendered without neutralization, an attacker who can insert arbitrary data into a Score entry can cause the victim’s browser to execute malicious JavaScript, potentially enabling theft of session cookies, defacement of the page, or other client‑side compromise of confidentiality and integrity for any user who views the affected content.

Affected Systems

The flaw affects the Wikimedia Foundation’s MediaWiki Score extension across the MediaWiki 1.43, 1.44, and 1.45 release branches. Any installation that uses the Score extension and has not applied the fix from the master branch is vulnerable. The issue was addressed in the current master and the official release branches for the mentioned MediaWiki versions.

Risk and Exploitability

The CVSS score of 6.9 places it in the high severity range, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. Attackers would typically need to supply data via the Score extension’s input interface, which, if exposed to untrusted users, provides a remote attack vector that can be leveraged from any connected client. While the impact is contained to the victim’s browser, the widespread nature of MediaWiki installations means the potential attack surface is large.

Generated by OpenCVE AI on April 8, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MediaWiki to version 1.45 or later, ensuring the Score extension is updated from the master branch.
  • Verify that the Score extension has been patched by checking the current extension code for the latest commit.
  • If updates cannot be applied immediately, restrict who can submit data to the Score extension and consider disabling the extension until a fix is available.

Generated by OpenCVE AI on April 8, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Wikimedia
Wikimedia mediawiki-score Extension
Vendors & Products Wikimedia
Wikimedia mediawiki-score Extension

Wed, 08 Apr 2026 22:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Score Extension. Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.

Wed, 08 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Apr 2026 22:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Score Extension.
Title Stored XSS in Score due to usage of non-reserved data attributes
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Wikimedia Mediawiki-score Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-04-08T22:08:23.300Z

Reserved: 2026-04-07T21:25:36.589Z

Link: CVE-2026-39936

cve-icon Vulnrichment

Updated: 2026-04-08T15:19:10.547Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-07T23:16:27.530

Modified: 2026-04-08T23:16:59.007

Link: CVE-2026-39936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:28:34Z

Weaknesses