CVE-2025-62695: Stored XSS through system messages
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Stored XSS.This issue affects Mediawiki - WikiLambda Extension: master.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62695?
CVE-2025-62695 is classified as a stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-62695?
To fix CVE-2025-62695, ensure you are using the latest version of the Mediawiki - WikiLambda Extension with the provided patches.
What systems are affected by CVE-2025-62695?
CVE-2025-62695 affects the Mediawiki - WikiLambda Extension developed by The Wikimedia Foundation.
What kind of attacks can be executed through CVE-2025-62695?
CVE-2025-62695 allows attackers to perform stored XSS attacks, potentially compromising user data.
How can I mitigate the risks of CVE-2025-62695?
To mitigate risks of CVE-2025-62695, implement input validation and output encoding to prevent malicious script execution.