CVE-2026-103584: attacker-controlled javascript license URL via XSS
Published Sep 30, 2026
·Updated
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS).
This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki CommonsMetadata extension=1.46, =1.45, =1.43
Event History
Sep 30, 2026
CVE Published
via MITRE·10:14 PM
Data Sourced
via MITRE·10:14 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects the MediaWiki CommonsMetadata extension versions 1.46, 1.45, and 1.43.
2
What must an attacker be able to do to exploit this issue?
The CVSS vector indicates high privileges are required and user interaction is required. Exploitation also has high attack complexity and depends on a pre-existing condition.
3
What is the likely impact if exploitation succeeds?
Successful exploitation can cause limited impact to confidentiality, integrity, and availability for both the vulnerable system and subsequent systems, according to the CVSS vector.