CVE-2025-62671
MEDIUMMediaWiki Cargo Extension < 3.8.3 - Stored Cross-Site Scripting
Title source: llmDescription
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: master.
References (2)
Core 2
Core References
Issue Tracking
https://phabricator.wikimedia.org/T402147
Various Sources
https://gerrit.wikimedia.org/r/1179707
Scores
CVSS v4
6.9
EPSS
0.0006
EPSS Percentile
17.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
mediawiki/cargo
0 - 3.8.3Packagist
The Wikimedia Foundation/Mediawiki - Cargo Extension
master
Published
Oct 18, 2025
Tracked Since
Feb 18, 2026