CVE-2026-100245: Stored XSS on Wikibase Special:SetSiteLink via unescaped system message
Published Sep 29, 2026
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS.
This issue affects Mediawiki - Wikibase Extension: from before 1.46.1, 1.45.5, 1.43.10.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki Wikibase Extension<1.46.1, <1.45.5, <1.43.10
Event History
Sep 29, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionWeakness
Frequently Asked Questions
1
Which releases are affected?
Affected versions are releases before 1.46.1, 1.45.5, and 1.43.10, as applicable to the deployed release branch. Updating to the listed release for the relevant branch addresses the affected version range.