PT-2026-99102 · Mediawiki · Cargo

CVE-2026-96875

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Mediawiki - Cargo extension versions prior to 3.9.5
Description Improper neutralization of input during web page generation leads to a stored cross-site scripting (XSS) issue. This occurs when the application fails to properly sanitize user-supplied data before including it in the HTML output, allowing an attacker to inject malicious scripts that are stored on the server and executed in the browsers of other users.
Recommendations Update Mediawiki - Cargo extension to version 3.9.5 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96875

Affected Products

Cargo