First published: Fri Apr 11 2025(Updated: )
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Version Compare Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Version Compare Extension: from 1.39 through 1.43.
Credit: c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | >=1.39<=1.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32078 is classified as a medium severity Cross-Site Scripting (XSS) vulnerability.
CVE-2025-32078 affects the Mediawiki - Version Compare Extension from versions 1.39 to 1.43.
To fix CVE-2025-32078, upgrade the Mediawiki - Version Compare Extension to a version above 1.43.
CVE-2025-32078 is an improper encoding or escaping of output vulnerability that allows for XSS.
Yes, CVE-2025-32078 can be exploited remotely to execute malicious scripts in users' browsers.