CVE-2025-32071: Wikibase CommonsInlineImageFormatter: i18n XSS
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32071?
CVE-2025-32071 has been classified as a moderate severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-32071?
To fix CVE-2025-32071, update the Mediawiki - Wikidata Extension to a version later than 1.43.
What is the nature of the vulnerability described in CVE-2025-32071?
CVE-2025-32071 is an improper input validation vulnerability allowing Cross-Site Scripting (XSS) from the widthheight message.
Which versions of Mediawiki - Wikidata Extension are affected by CVE-2025-32071?
CVE-2025-32071 affects Mediawiki - Wikidata Extension versions from 1.39 through 1.43.
Is CVE-2025-32071 specific to any software vendor?
Yes, CVE-2025-32071 specifically affects the Wikimedia Foundation's Mediawiki - Wikidata Extension.