CVE-2025-62656: GlobalBlocking Special:GlobalBlockList vulnerable to message key stored XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki GlobalBlocking extension allows Stored XSS.This issue affects MediaWiki GlobalBlocking extension: 1.43, 1.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62656?
CVE-2025-62656 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-62656?
To fix CVE-2025-62656, update the MediaWiki GlobalBlocking extension to version 1.45 or later.
What type of vulnerability is CVE-2025-62656?
CVE-2025-62656 is an Improper Neutralization of Input During Web Page Generation vulnerability, specifically allowing stored XSS.
Which versions of MediaWiki are affected by CVE-2025-62656?
CVE-2025-62656 affects MediaWiki GlobalBlocking extension versions 1.43 and 1.44.
Can CVE-2025-62656 be exploited remotely?
Yes, CVE-2025-62656 can be exploited remotely by attackers through malicious scripts that target users of the affected MediaWiki extension.