CVE-2025-62657: Stored XSS through system messages in PageForms
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PageForms extension allows Stored XSS.This issue affects MediaWiki PageForms extension: 1.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62657?
CVE-2025-62657 is classified as a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-62657?
To fix CVE-2025-62657, update the MediaWiki PageForms extension to the latest version where the vulnerability is patched.
What versions of MediaWiki PageForms are affected by CVE-2025-62657?
CVE-2025-62657 affects the MediaWiki PageForms extension version 1.44.
What impact does CVE-2025-62657 have on users?
The impact of CVE-2025-62657 includes the potential for attackers to execute malicious scripts in the context of a victim's browser.
Is user authentication necessary to exploit CVE-2025-62657?
No, CVE-2025-62657 can be exploited without user authentication, allowing for broader attack vectors.