CVE-2025-32072: HTML injection in feed output from i18n message
Published Apr 11, 2025
·Updated
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.
Affected Software
1 affected component
Wikimedia Foundation Mediawiki Core - Feed Utils>=1.39<1.43
Event History
Apr 11, 2025
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32072?
CVE-2025-32072 has a moderate severity level due to the potential for WebView injection attacks.
2
How do I fix CVE-2025-32072?
To fix CVE-2025-32072, upgrade MediaWiki Core - Feed Utils to version 1.44 or later.
3
What versions are affected by CVE-2025-32072?
CVE-2025-32072 affects MediaWiki Core - Feed Utils versions from 1.39 through 1.43.
4
What type of vulnerability is CVE-2025-32072?
CVE-2025-32072 is classified as an Improper Encoding or Escaping of Output vulnerability.
5
Who is impacted by CVE-2025-32072?
Users and administrators of MediaWiki Core - Feed Utils from versions 1.39 through 1.43 are impacted by CVE-2025-32072.