CVE-2026-39838: ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSS
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage Extension allows XSS Targeting Non-Script Elements. The issue has been remediated on the master branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39838?
The severity of CVE-2026-39838 is classified as a medium risk due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2026-39838?
To fix CVE-2026-39838, upgrade the MediaWiki ProofreadPage extension to version 1.45 or later.
What systems are affected by CVE-2026-39838?
CVE-2026-39838 affects the Wikimedia Foundation MediaWiki ProofreadPage extension versions prior to 1.45.
What types of attacks can CVE-2026-39838 facilitate?
CVE-2026-39838 can facilitate cross-site scripting (XSS) attacks targeting non-script elements.
Is user input involved in CVE-2026-39838?
Yes, CVE-2026-39838 involves improper sanitization of multiline styles in user input during web page generation.