CVE 5.8 MEDIUM

Stored XSS through system messages in PageForms_CVE-2025-62657

5.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:C/RE:L/U:Amber

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PageForms extension allows Stored XSS.This issue affects MediaWiki PageForms extension: 1.44.

Basic Information

ID CVE-2025-62657
Source wikimedia-foundation
Published Oct 20, 2025 at 20:19
Modified Oct 20, 2025 at 20:36

Affected Product

Vendor The Wikimedia Foundation
Product MediaWiki PageForms extension
Version 1.44
Affected Versions The Wikimedia Foundation MediaWiki PageForms extension 1.44

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.