CVE-2025-67484: Action API xslt option allows JavaScript execution by administrators who are not interface administrators
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php.
This issue affects MediaWiki: from before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67484?
CVE-2025-67484 has been classified with a high severity level due to its potential for JavaScript execution by unauthorized users.
How do I fix CVE-2025-67484?
To fix CVE-2025-67484, update your MediaWiki installation to version 1.39.16 or 1.43.6 and above.
Who is affected by CVE-2025-67484?
CVE-2025-67484 affects MediaWiki versions prior to 1.39.16 and between 1.43.6 and 1.45.1.
What type of vulnerability is CVE-2025-67484?
CVE-2025-67484 is a security vulnerability that allows JavaScript execution via the Action API xslt option.
Can administrators mitigate CVE-2025-67484 without updating?
Without updating, administrators cannot fully mitigate CVE-2025-67484, as it requires a patch to eliminate the vulnerability.