CVE-2026-103445: CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) in The Wikimedia Foundation MediaWiki Page_Forms extension
A stored cross-site scripting (XSS) vulnerability exists in The Wikimedia Foundation MediaWiki Page_Forms extension due to improper neutralization of script-related HTML tags. This affects versions 1.43, 1.45, and 1.46 of the extension. The vulnerability has a low severity rating and a CVSS score of 1.2. No patch or official remediation information is provided in the available data.
AI Analysis
Technical Summary
CVE-2026-103445 is a stored XSS vulnerability in the MediaWiki Page_Forms extension caused by improper neutralization of script-related HTML tags in web pages. This allows an attacker to inject malicious scripts that are stored and executed when users view the affected pages. The issue affects versions 1.43, 1.45, and 1.46 of the extension. The vulnerability has a low CVSS 4.0 score of 1.2, indicating limited impact and exploitability. No vendor advisory or patch information is currently provided.
Potential Impact
The vulnerability allows stored cross-site scripting attacks, which could lead to script execution in the context of affected users. However, the low CVSS score and severity indicate that the impact is limited, possibly due to required privileges or user interaction. There are no known exploits in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should exercise caution with untrusted input in the affected versions of the Page_Forms extension.
CVE-2026-103445: CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) in The Wikimedia Foundation MediaWiki Page_Forms extension
Description
A stored cross-site scripting (XSS) vulnerability exists in The Wikimedia Foundation MediaWiki Page_Forms extension due to improper neutralization of script-related HTML tags. This affects versions 1.43, 1.45, and 1.46 of the extension. The vulnerability has a low severity rating and a CVSS score of 1.2. No patch or official remediation information is provided in the available data.
CVSS v4.0
Score 1.2low
Affected software
The Wikimedia Foundation
MediaWiki Page_Forms extension
pkg:github/wikimedia/mediawiki-page-forms-extensionRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103445 is a stored XSS vulnerability in the MediaWiki Page_Forms extension caused by improper neutralization of script-related HTML tags in web pages. This allows an attacker to inject malicious scripts that are stored and executed when users view the affected pages. The issue affects versions 1.43, 1.45, and 1.46 of the extension. The vulnerability has a low CVSS 4.0 score of 1.2, indicating limited impact and exploitability. No vendor advisory or patch information is currently provided.
Potential Impact
The vulnerability allows stored cross-site scripting attacks, which could lead to script execution in the context of affected users. However, the low CVSS score and severity indicate that the impact is limited, possibly due to required privileges or user interaction. There are no known exploits in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should exercise caution with untrusted input in the affected versions of the Page_Forms extension.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- wikimedia-foundation
- Date Reserved
- 2026-09-30T15:41:01.270Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd72572a4e24523d8ec0fc
Added to database: 09/30/2026, 20:34:31 UTC
Last enriched: 09/30/2026, 20:48:32 UTC
Last updated: 10/01/2026, 04:00:39 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.