CVE-2025-61651: i18n XSS through Special:CheckUser CheckUser helper
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser/checkuser/checkUserHelper/buildUserElement.Js.
This issue affects CheckUser: from before 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61651?
CVE-2025-61651 has been classified with a severity rating that indicates a significant risk due to Cross-site Scripting (XSS) vulnerabilities.
How do I fix CVE-2025-61651?
To fix CVE-2025-61651, update your Wikimedia Foundation CheckUser to at least version 1.44.1 or higher.
What types of attacks are associated with CVE-2025-61651?
CVE-2025-61651 is associated with Cross-site Scripting (XSS) attacks that can be executed due to improper neutralization of input.
What affected software is impacted by CVE-2025-61651?
CVE-2025-61651 specifically affects the Wikimedia Foundation CheckUser version up to, but not including, 1.44.1.
Is there a known exploit for CVE-2025-61651?
As of now, there are no specific public exploits available for CVE-2025-61651, but the vulnerability itself poses a risk for XSS attacks.