维基媒体基金会(Wikimedia Foundation)的 MediaWiki Page_Forms 扩展存在一个“网页中未正确中和脚本相关 HTML 标签(基础型 XSS)”的漏洞,可导致存储型跨站脚本攻击(Stored XSS)。 该问题影响 MediaWiki Page_Forms 扩展的以下版本:1.46、1.45 和 1.43。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The Wikimedia Foundation | MediaWiki Page_Forms extension | 1.46 |
affected |
1.45 |
affected | ||
1.43 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Wikimedia Foundation | MediaWiki Page_Forms extension | 1.46 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103446 | 7.4 HIGH | WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments |
| CVE-2026-103441 | 7.2 HIGH | Unauthenticated arbitrary file deletion through Wikibase serialized entity parsing |
| CVE-2026-103442 | 7.2 HIGH | MergeAccount PHP object injection via session-key substitution |
| CVE-2026-103440 | 1.2 LOW | pagetriagelist discloses suppressed reviewer usernames |
| CVE-2026-103585 | 1.2 LOW | attacker-controlled javascript license URL via XSS |
| CVE-2026-103443 | 1.1 LOW | API permits session-seeded javascript URL XSS |
| CVE-2026-103444 | 1.1 LOW | Stored XSS through system messages in WikiForum |
| CVE-2026-103437 | 1.1 LOW | ReadingLists imported metadata permits JavaScript URL XSS |
| CVE-2026-103584 | 1.1 LOW | attacker-controlled javascript license URL via XSS |
| CVE-2026-103438 | 0.3 LOW | Various rawParams() and escaped() updates to prevent XSS in Wikistories extension |
| CVE-2026-103439 | 0.3 LOW | Various rawParams() and escaped() updates to prevent XSS in Wikibase extension |
No comments yet