CVE-2025-3469: i18n XSS vulnerability in HTMLMultiSelectField when sections are used
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php.
This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3469?
CVE-2025-3469 has been classified as a moderate severity Cross-site Scripting (XSS) vulnerability affecting MediaWiki.
What versions of MediaWiki are affected by CVE-2025-3469?
CVE-2025-3469 affects MediaWiki versions prior to 1.39.12 and between 1.42.6 to 1.43.1.
How do I fix CVE-2025-3469?
To fix CVE-2025-3469, upgrade your MediaWiki installation to version 1.39.12 or later, or ensure you are outside the vulnerable range of 1.42.6 to 1.43.1.
What kind of vulnerability is CVE-2025-3469?
CVE-2025-3469 is an Improper Neutralization of Input During Web Page Generation, commonly known as a Cross-site Scripting (XSS) vulnerability.
Who is affected by CVE-2025-3469?
Users and administrators of Wikimedia Foundation's MediaWiki software prior to version 1.39.12 and within the specified range are affected by CVE-2025-3469.