CVE-2025-62670: Stored XSS through a system message in FlexDiagrams
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - FlexDiagrams Extension allows Stored XSS.This issue affects Mediawiki - FlexDiagrams Extension: master.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62670?
CVE-2025-62670 is classified as a stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-62670?
To fix CVE-2025-62670, update the Mediawiki - FlexDiagrams Extension to the latest version that addresses this vulnerability.
What software is affected by CVE-2025-62670?
CVE-2025-62670 affects the Mediawiki - FlexDiagrams Extension developed by the Wikimedia Foundation.
What type of vulnerability is CVE-2025-62670?
CVE-2025-62670 is an improper neutralization of input during web page generation vulnerability that allows for stored XSS.
How does CVE-2025-62670 impact users?
CVE-2025-62670 can allow attackers to execute malicious scripts in the context of the user's session, posing serious security risks.