CVE-2025-32077
Description
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Extension:SimpleCalendar allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Extension:SimpleCalendar: from 1.39 through 1.43.
CWE
- CWE-20 — CWE-20 Improper Input Validation
Affected
- The Wikimedia Foundation / Mediawiki - Extension:SimpleCalendar — v=1.39 ≤1.43 [affected]
CVSS
- 4.0 score=6.9 severity=MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
References
- https://phabricator.wikimedia.org/T383472
- https://gerrit.wikimedia.org/r/q/Ic5b5ce8f7791026eff1aafffb32a68f3aab119be
Source
cvelistV5-main/cves/2025/32xxx/CVE-2025-32077.json