CVE-2026-103439: Various rawParams() and escaped() updates to prevent XSS in Wikibase extension
Published Sep 30, 2026
·Updated
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS).
This issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43.
Affected Software
1 affected component
Wikimedia Foundation Wikibase Extension=1.46, =1.45, =1.43
Event History
Sep 30, 2026
CVE Published
via MITRE·05:34 PM
Data Sourced
via MITRE·05:34 PM
DescriptionWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which versions should be investigated?
The affected MediaWiki Wikibase extension versions are 1.46, 1.45, and 1.43.
2
What access and conditions does exploitation require?
The CVSS vector indicates local access, high privileges, high attack complexity, and user interaction are required. Successful exploitation may affect confidentiality, integrity, and availability at a low level.