CVE-2026-30917

All FrameworksMediaWikiCWE-79CVE-2026-30917

CVE-2026-30917

State: PUBLISHED · Published: 2026-03-09 · Updated: 2026-03-10 · Assigner: GitHub_M
Description
Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This vulnerability is fixed in 2.1.1.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2026/30xxx/CVE-2026-30917.json