CVE-2025-62693: Stored XSS through system messages in LastModified
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - LastModified Extension allows Stored XSS.This issue affects Mediawiki - LastModified Extension: from master before 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62693?
CVE-2025-62693 is categorized as a medium-severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-62693?
To mitigate CVE-2025-62693, upgrade the Mediawiki - LastModified Extension to version 1.39 or later.
What type of vulnerability is CVE-2025-62693?
CVE-2025-62693 is an improper neutralization of input during web page generation, leading to stored cross-site scripting (XSS).
Which versions of Mediawiki - LastModified Extension are affected by CVE-2025-62693?
CVE-2025-62693 affects all versions of the Mediawiki - LastModified Extension prior to version 1.39.
Can CVE-2025-62693 lead to data leakage?
Yes, if exploited, CVE-2025-62693 could allow attackers to execute scripts that may lead to data leakage.