Mediawiki · Cargo · CVE-2026-103049
**Name of the Vulnerable Software and Affected Versions**
Mediawiki - Cargo extension versions prior to 1.46.1
**Description**
Improper neutralization of input during web page generation leads to a Reflected Cross-Site Scripting (XSS) issue. This occurs when an application includes untrusted data in a web page without proper validation or encoding, allowing an attacker to execute malicious scripts in the victim's browser.
**Recommendations**
Update Mediawiki - Cargo extension to version 1.46.1 or later.