CVE-2025-6594: XSS in Special:ApiSandbox
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandbox.Js.
This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6594?
CVE-2025-6594 is classified as a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2025-6594?
To fix CVE-2025-6594, update your Wikimedia Foundation MediaWiki installation to a version above 1.39.12.
What products are affected by CVE-2025-6594?
CVE-2025-6594 affects all versions of Wikimedia Foundation MediaWiki from 1.27.0 to 1.39.12.
What type of vulnerability is CVE-2025-6594?
CVE-2025-6594 is an XSS (Cross-site Scripting) vulnerability involving improper input neutralization.
Is there a workaround for CVE-2025-6594?
Currently, there are no documented workarounds for CVE-2025-6594; the best course of action is to apply the software update.