CVE-2026-39837
MEDIUMStored XSS through the dynamic table format in Cargo
Title source: cnaDescription
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.
Scores
CVSS v3
5.4
EPSS
0.0003
EPSS Percentile
8.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-80
Status
published
Products (2)
mediawiki/cargo
< 3.8.7
Wikimedia Foundation/Mediawiki - Cargo Extension
< 3.8.7
Published
Apr 07, 2026
Tracked Since
Apr 08, 2026