CVE-2025-61644: i18n XSS through Special:Watchlist
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/WatchlistTopSectionWidget.Js.
This issue affects MediaWiki: from before > fb856ce9cf121e046305116852cca4899ecb48ca.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61644?
CVE-2025-61644 is classified as a moderate severity vulnerability due to the potential for exploitation through cross-site scripting.
How do I fix CVE-2025-61644?
To fix CVE-2025-61644, update to the latest version of Wikimedia Foundation MediaWiki where this vulnerability has been addressed.
Who is affected by CVE-2025-61644?
CVE-2025-61644 affects users of Wikimedia Foundation MediaWiki versions before fb856ce9cf121e046305116852cca4899ecb48ca.
What type of vulnerability is CVE-2025-61644?
CVE-2025-61644 is an XSS (Cross-site Scripting) vulnerability that arises from improper input neutralization during web page generation.
What are the impacts of CVE-2025-61644?
The impact of CVE-2025-61644 includes the risk of malicious scripts being executed in the context of users' browsers, leading to data theft or manipulation.