CVE-2026-103051: Stored i18n XSSs in CentralNotice
Published Sep 29, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS.
This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki CentralNotice extension<1.46.1, <1.45.5, <1.43.10
Event History
Sep 29, 2026
CVE Published
via MITRE·11:13 PM
Data Sourced
via MITRE·11:13 PM
DescriptionWeakness
Sep 30, 2026
Data Sourced
via NVD·12:16 AM
DescriptionWeakness
Frequently Asked Questions
1
Which CentralNotice versions need to be remediated?
The issue affects CentralNotice versions before 1.46.1, 1.45.5, and 1.43.10. Upgrade to the applicable fixed release for your MediaWiki release line.
2
What is the impact if the vulnerability is exploited?
Successful exploitation allows stored cross-site scripting during web page generation. Malicious input can be retained and later executed in users' browsers when affected content is rendered.