CVE-2025-62664: Stored XSS through a system message in ImageRating
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ImageRating Extension allows Stored XSS.This issue affects Mediawiki - ImageRating Extension: from master before 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62664?
CVE-2025-62664 has a medium severity due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-62664?
To mitigate CVE-2025-62664, upgrade the Mediawiki - ImageRating Extension to version 1.39 or later.
Which versions of the Mediawiki - ImageRating Extension are affected by CVE-2025-62664?
CVE-2025-62664 affects all versions of the Mediawiki - ImageRating Extension prior to 1.39.
What kind of vulnerability is CVE-2025-62664?
CVE-2025-62664 is an improper neutralization of input vulnerability, specifically allowing for stored XSS.
Who is responsible for maintaining the Mediawiki - ImageRating Extension affected by CVE-2025-62664?
The Wikimedia Foundation is responsible for maintaining the Mediawiki - ImageRating Extension affected by CVE-2025-62664.