CVE-2025-11937: Stored XSS through a system message in SecurePoll
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - SecurePoll Extension allows Stored XSS.This issue affects Mediawiki - SecurePoll Extension: master.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11937?
CVE-2025-11937 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-11937?
To mitigate CVE-2025-11937, update to the latest version of the Mediawiki - SecurePoll Extension where the vulnerability has been patched.
What type of vulnerability is CVE-2025-11937?
CVE-2025-11937 is an improper neutralization of input vulnerability during web page generation, leading to stored cross-site scripting (XSS).
Who is affected by CVE-2025-11937?
CVE-2025-11937 affects users of the Wikimedia Foundation Mediawiki - SecurePoll Extension.
Can CVE-2025-11937 lead to data compromise?
Yes, CVE-2025-11937 can lead to data compromise as attackers may execute malicious scripts in the context of the user’s browser.