CVE-2025-21612

HIGH

TabberNeue 1.9.1-2.7.1 - Cross-Site Scripting in TabberTransclude.php

Title source: llm
STIX 2.1

Description

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.

Scores

CVSS v3 8.6
EPSS 0.0049
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79 CWE-80
Status published
Products (3)
StarCitizenTools/mediawiki-extensions-TabberNeue >= 1.9.1, < 2.7.2
StarCitizenTools/mediawiki-extensions-TabberNeue >= d8c3db4e5935476e496d979fb01f775d3d3282e6, < f229cab099c69006e25d4bad3579954e481dc566
starcitizentools/tabber-neue 1.9.1 - 2.7.2Packagist
Published Jan 06, 2025
Tracked Since Feb 18, 2026