在网页生成过程中对输入进行中立化处理不当(XSS 或“跨站脚本”)漏洞存在于 Wikimedia 基金会 MediaWiki 的 TemplateSandbox 扩展中,可导致跨站脚本攻击(XSS)。 受影响的 MediaWiki TemplateSandbox 扩展版本为:1.46.1 之前、1.45.5 之前或 1.43.10 之前的所有版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Wikimedia Foundation | Mediawiki - TemplateSandbox Extension | *< 1.46.1, 1.45.5, 1.43.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Wikimedia Foundation | Mediawiki - TemplateSandbox Extension | * ~ 1.46.1, 1.45.5, 1.43.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100382 | 10.0 CRITICAL | Unauthenticated remote code execution through wikitext in ExternalData |
| CVE-2026-100377 | 6.9 MEDIUM | Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbst |
| CVE-2026-100381 | 5.3 MEDIUM | UploadWizard Flickr collection and set titles allow DOM XSS |
| CVE-2026-100380 | 5.3 MEDIUM | Reflected XSS in Wikibase Special:SetLabel language validation |
| CVE-2026-100378 | 5.3 MEDIUM | Missing permission check in the Translate sandbox doRemind action |
| CVE-2026-100379 | 5.3 MEDIUM | Cross-request disclosure of CentralAuth cookies in Wikipedia Android App |
| CVE-2026-100383 | 4.8 MEDIUM | Stored i18n XSS in WikiLambda's VisualEditor integration |
No comments yet