CVE-2026-103444: Stored XSS through system messages in WikiForum
Published Sep 30, 2026
·Updated
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS.
This issue affects MediaWiki WikiForum extension: master.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki WikiForum extension=master
Event History
Sep 30, 2026
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are identified as affected?
The affected target is the Wikimedia Foundation MediaWiki WikiForum extension on the master branch. No released version range or fixed version is provided.
2
Where does the untrusted content need to appear for exploitation?
The issue is described as stored XSS through system messages. Exploitation depends on script-related HTML tags not being properly neutralized when rendered in a web page.