CVE-2025-62652

All FrameworksMediaWikiCWE-79CVE-2025-62652

CVE-2025-62652

State: PUBLISHED · Published: 2025-10-17 · Updated: 2025-10-20 · Assigner: wikimedia-foundation
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/62xxx/CVE-2025-62652.json