CVE-2026-22711: Stored XSS through system messages in WikiLove
Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the master branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22711?
CVE-2026-22711 has been assigned a severity rating indicating a moderate risk due to the potential for stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2026-22711?
To fix CVE-2026-22711, update the MediaWiki Wikilove extension to the latest version where the vulnerability has been addressed.
What causes CVE-2026-22711?
CVE-2026-22711 is caused by improper neutralization of alternate XSS syntax in system messages within the Wikimedia Foundation MediaWiki Wikilove extension.
Who is affected by CVE-2026-22711?
Users of the MediaWiki Wikilove extension are affected by CVE-2026-22711, particularly those who do not have the latest updates installed.
What are the potential impacts of CVE-2026-22711?
The potential impacts of CVE-2026-22711 include unauthorized script execution in users' browsers, which can lead to data theft or session hijacking.