CVE-2025-11937

All FrameworksMediaWikiCWE-79CVE-2025-11937

CVE-2025-11937

State: PUBLISHED · Published: 2025-10-18 · Updated: 2025-10-20 · Assigner: wikimedia-foundation
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - SecurePoll Extension allows Stored XSS.This issue affects Mediawiki - SecurePoll Extension: master.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/11xxx/CVE-2025-11937.json