PT-2026-99102 · Mediawiki · Cargo
CVE-2026-96875
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Mediawiki - Cargo extension versions prior to 3.9.5
Description
Improper neutralization of input during web page generation leads to a stored cross-site scripting (XSS) issue. This occurs when the application fails to properly sanitize user-supplied data before including it in the HTML output, allowing an attacker to inject malicious scripts that are stored on the server and executed in the browsers of other users.
Recommendations
Update Mediawiki - Cargo extension to version 3.9.5 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cargo