CVE-2025-32071
Description
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.
CWE
- CWE-20 — CWE-20 Improper Input Validation
Affected
- The Wikimedia Foundation / Mediawiki - Wikidata Extension — v=1.39 ≤1.43 [affected]
CVSS
- (none)
References
- https://phabricator.wikimedia.org/T389369
- https://gerrit.wikimedia.org/r/q/Iac1f1c27054bfd1a4a4251281ab8c72f59204a90
Source
cvelistV5-main/cves/2025/32xxx/CVE-2025-32071.json