CVE-2025-61636: Codex Special:Block vulnerable to message key XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLButtonField.Php.
This issue affects MediaWiki: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61636?
The severity of CVE-2025-61636 is classified as high due to its potential for Cross-site Scripting (XSS) exploitation.
How do I fix CVE-2025-61636?
To fix CVE-2025-61636, upgrade your MediaWiki installation to version 1.44.1 or later.
What versions of MediaWiki are affected by CVE-2025-61636?
MediaWiki versions up to 1.39.14 and versions between 1.43.4 and 1.44.1 are affected by CVE-2025-61636.
What types of attacks does CVE-2025-61636 enable?
CVE-2025-61636 enables Cross-site Scripting (XSS) attacks which can lead to unauthorized actions and data theft.
Who is responsible for addressing CVE-2025-61636?
The Wikimedia Foundation is responsible for addressing CVE-2025-61636 in their MediaWiki software.