CVE-2025-61638: Sanitizer::validateAttributes data-XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php.
This issue affects MediaWiki: from before 1.39.14, 1.43.4, 1.44.1; Parsoid: from before 0.16.6, 0.20.4, 0.21.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61638?
CVE-2025-61638 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2025-61638?
To fix CVE-2025-61638, update Wikimedia Foundation MediaWiki to version 1.39.14 or higher and Parsoid to version 0.21.1 or higher.
What systems are affected by CVE-2025-61638?
CVE-2025-61638 affects Wikimedia Foundation MediaWiki versions prior to 1.39.14, 1.43.4, and 1.44.1, and Parsoid versions prior to 0.16.6, 0.20.4, and 0.21.1.
What types of attacks can CVE-2025-61638 facilitate?
CVE-2025-61638 can facilitate cross-site scripting (XSS) attacks by improperly handling user input during web page generation.
Is there a known exploit for CVE-2025-61638?
As of now, there are no publicly known exploits for CVE-2025-61638, but it is important to apply patches promptly to mitigate risks.