PT-2026-24147 · Mediawiki · Kbucket

·

CVE-2026-30917

·

Published

2026-03-09

·

Updated

2026-03-10

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Bucket versions prior to 2.1.1
Description Bucket is a MediaWiki extension used to store and retrieve structured data on articles. A stored cross-site scripting (XSS) issue exists that allows malicious code to be inserted into any Bucket table field with a PAGE type. This code will execute when a user views the corresponding Bucket namespace page.
Recommendations Update to Bucket version 2.1.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30917
GHSA-8JRP-37WC-5V7C

Affected Products

Kbucket