CVE-2025-61638

MEDIUM

MediaWiki <1.39.14, 1.43.4, 1.44.1 - XSS

Title source: llm

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoid: from * before 0.16.6, 0.20.4, 0.21.1.

Exploits (2)

github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-61638
nomisec WORKING POC 1 stars
by gui-ying233 · poc
https://github.com/gui-ying233/CVE-2025-61638

Scores

CVSS v3 4.8
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
mediawiki/mediawiki < 1.39.14
wikimedia/parsoid < 0.16.6
Wikimedia Foundation/MediaWiki < 1.39.14, 1.43.4, 1.44.1
Wikimedia Foundation/Parsoid < 0.16.6, 0.20.4, 0.21.1
Published Feb 03, 2026
Tracked Since Feb 18, 2026