CVE-2025-62659: The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki CookieConsent extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki CookieConsent extension: from v0.1.0 before v2.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62659?
The severity of CVE-2025-62659 is rated as critical due to its potential for allowing Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-62659?
To fix CVE-2025-62659, upgrade the MediaWiki CookieConsent extension to version 2.0.0 or later.
What software is affected by CVE-2025-62659?
CVE-2025-62659 affects The Wikimedia Foundation MediaWiki CookieConsent extension from version 0.1.0 up to but not including version 2.0.0.
What type of vulnerability is CVE-2025-62659?
CVE-2025-62659 is classified as an Improper Neutralization of Input During Web Page Generation, specifically a Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-62659 be exploited remotely?
Yes, CVE-2025-62659 can be exploited remotely by an attacker through malicious inputs on vulnerable MediaWiki sites.