CVE-2026-30977: RenderBlocking has Stored XSS in renderblocking-css with Inline Assets mode
RenderBlocking is a MediaWiki extension that allows interface administrators to specify render-blocking CSS and JavaScript. Prior to 0.1.1, there is Stored XSS in renderblocking-css with Inline Assets mode. $wgRenderBlockingInlineAssets = true and editsitecss user rights are required. This vulnerability is fixed in 0.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30977?
CVE-2026-30977 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-30977?
To fix CVE-2026-30977, upgrade the MediaWiki RenderBlocking extension to version 0.1.1 or later.
What is the impact of CVE-2026-30977?
The impact of CVE-2026-30977 allows attackers to inject malicious scripts through stored XSS, compromising the security of users viewing affected pages.
Which versions of MediaWiki RenderBlocking are vulnerable to CVE-2026-30977?
Versions of MediaWiki RenderBlocking prior to 0.1.1 are vulnerable to CVE-2026-30977.
Who is affected by CVE-2026-30977?
Administrators using MediaWiki with the RenderBlocking extension prior to version 0.1.1 are affected by CVE-2026-30977.