CVE-2025-49576

MEDIUM

Citizen < 3.3.1 - XSS

Title source: rule
STIX 2.1

Description

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1.

Scores

CVSS v3 6.5
EPSS 0.0016
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
starcitizen.tools/citizen < 3.3.1
starcitizentools/citizen-skin 2.31.0 - 3.3.1Packagist
Published Jun 12, 2025
Tracked Since Feb 18, 2026