PT-2025-39387 · Mediawiki · Embedvideo Extension

CVE-2025-59839

·

Published

2025-09-24

·

Updated

2025-09-25

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions EmbedVideo Extension versions prior to 4.0.0
Description The EmbedVideo Extension for MediaWiki, which includes a parser function called #ev and parser tags for embedding video clips, contains a flaw. Versions 4.0.0 and earlier permit the addition of arbitrary attributes to an HTML element, potentially leading to stored cross-site scripting (XSS) through wikitext. The issue was addressed with commit 4e075d3.
Recommendations Update to EmbedVideo Extension version 4.0.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59839
GHSA-4J5H-MVJ3-M48V

Affected Products

Embedvideo Extension