CVE-2026-100380: Reflected XSS in Wikibase Special:SetLabel language validation
Published Sep 25, 2026
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS).
This issue affects Mediawiki - Wikibase Extension: from before 1.46.1, 1.45.5, 1.43.10.
Affected Software
1 affected component
Wikimedia Foundation Wikibase Extension<1.46.1, <1.45.5, <1.43.10
Event History
Sep 25, 2026
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be checked for exposure?
Check installations of the Wikimedia Foundation Wikibase Extension. The issue affects versions before 1.46.1, 1.45.5, and 1.43.10.
2
How can I determine whether an installation needs remediation?
Identify the installed Wikibase Extension version and compare it with the affected version ranges. Installations running a version earlier than the listed fixed release for their release line are affected.