CVE-2025-61645: CodexTablePager has i18n XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/pager/CodexTablePager.Php.
This issue affects MediaWiki: from before 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61645?
The severity of CVE-2025-61645 is classified as moderate due to its XSS vulnerability that could be exploited to execute scripts in the context of the user's browser.
How do I fix CVE-2025-61645?
To fix CVE-2025-61645, ensure that you upgrade your MediaWiki installation to version 1.44.1 or later, where the vulnerability has been addressed.
What versions of MediaWiki are affected by CVE-2025-61645?
CVE-2025-61645 affects MediaWiki versions up to, but not including, version 1.44.1.
What type of vulnerability is CVE-2025-61645?
CVE-2025-61645 is characterized as an improper neutralization of input during web page generation, leading to potential Cross-site Scripting (XSS) attacks.
Who is responsible for the CVE-2025-61645 vulnerability?
CVE-2025-61645 was identified within the CodexTablePager component of Wikimedia Foundation's MediaWiki software.