CVE-2025-62694: Stored XSS through a system message
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLove Extension allows Stored XSS.This issue affects Mediawiki - WikiLove Extension: 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62694?
CVE-2025-62694 is classified as a moderate severity Stored XSS vulnerability.
How do I fix CVE-2025-62694?
To fix CVE-2025-62694, update the Mediawiki - WikiLove Extension to version 1.40 or later to ensure proper input sanitization.
What systems are affected by CVE-2025-62694?
CVE-2025-62694 affects the Mediawiki - WikiLove Extension version 1.39.
What type of vulnerability is CVE-2025-62694?
CVE-2025-62694 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-site Scripting (XSS).
What are the potential impacts of CVE-2025-62694?
The potential impacts of CVE-2025-62694 include unauthorized script execution in the user's browser, leading to data theft or account compromise.