CVE-2025-6595: XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from before 1.39.13, 1.42.7, 1.43.2, 1.44.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6595?
The severity of CVE-2025-6595 is classified as high due to its potential for Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-6595?
To fix CVE-2025-6595, update the MultimediaViewer to version 1.39.13 or later, or to 1.42.7, 1.43.2, or 1.44.0.
What versions of MultimediaViewer are affected by CVE-2025-6595?
CVE-2025-6595 affects MultimediaViewer versions prior to 1.39.13, 1.42.7, 1.43.2, and 1.44.0.
What kind of vulnerability is CVE-2025-6595?
CVE-2025-6595 is an Improper Neutralization of Input During Web Page Generation vulnerability, specifically an XSS vulnerability.
Is there any immediate risk if CVE-2025-6595 is unpatched?
Yes, if left unpatched, CVE-2025-6595 can allow attackers to execute malicious scripts in the context of a user's session.