CVE-2025-61656: XSS when pasting into VE
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation VisualEditor. This vulnerability is associated with program files src/ce/ve.Ce.ClipboardHandler.Js.
This issue affects VisualEditor: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61656?
The severity of CVE-2025-61656 is classified as medium due to potential cross-site scripting risks.
How do I fix CVE-2025-61656?
To fix CVE-2025-61656, update to the latest version of Wikimedia Foundation VisualEditor, specifically version 1.39.15 or higher.
What software is affected by CVE-2025-61656?
CVE-2025-61656 affects Wikimedia Foundation VisualEditor versions up to and including 1.39.14.
What type of vulnerability is CVE-2025-61656?
CVE-2025-61656 is an improper neutralization of input during web page generation, commonly referred to as Cross-site Scripting (XSS).
What kind of attack can CVE-2025-61656 enable?
CVE-2025-61656 can enable attackers to execute arbitrary JavaScript in the context of a user's session, potentially leading to data theft or account hijacking.