CVE-2026-0670: Stored XSS through a system message and a user-provided parameter in ProofreadPage
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage Extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - ProofreadPage Extension: 1.45, 1.44, 1.43, 1.39.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0670?
CVE-2026-0670 has a high severity rating due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2026-0670?
To fix CVE-2026-0670, update the MediaWiki - ProofreadPage Extension to version 1.46 or later.
Which versions are affected by CVE-2026-0670?
CVE-2026-0670 affects MediaWiki - ProofreadPage Extension versions 1.39 to 1.45.
What type of vulnerability is CVE-2026-0670?
CVE-2026-0670 is classified as an Improper Neutralization of Input During Web Page Generation vulnerability, specifically XSS.
What systems are vulnerable to CVE-2026-0670?
Systems using the affected versions of the MediaWiki - ProofreadPage Extension are vulnerable to CVE-2026-0670.