CVE-2025-21612

All FrameworksMediaWikiCWE-79CVE-2025-21612

CVE-2025-21612

State: PUBLISHED · Published: 2025-01-06 · Updated: 2025-08-26 · Assigner: GitHub_M
Description
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/21xxx/CVE-2025-21612.json