Mediawiki · Charts Extension · CVE-2026-14358
**Name of the Vulnerable Software and Affected Versions**
Mediawiki - Charts Extension versions prior to 1.43.9
Mediawiki - Charts Extension versions prior to 1.44.6
Mediawiki - Charts Extension versions prior to 1.45.4
**Description**
Improper neutralization of input during web page generation allows for Stored Cross-Site Scripting (XSS) within the pie chart tooltip. The issue occurs via the `Data:*.tab` field title.
**Recommendations**
Update to version 1.43.9 or later.
Update to version 1.44.6 or later.
Update to version 1.45.4 or later.