CVE-2026-39933: Multiple XSS vulnerabilities in GlobalWatchlist
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the master branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39933?
CVE-2026-39933 has a moderate severity rating due to its potential for Cross-Site Scripting exploits.
How do I fix CVE-2026-39933?
To fix CVE-2026-39933, update the GlobalWatchlist extension to the latest version available in the master branch.
What systems are affected by CVE-2026-39933?
CVE-2026-39933 affects the GlobalWatchlist extension of Wikimedia Foundation's MediaWiki software.
What type of vulnerability is CVE-2026-39933?
CVE-2026-39933 is classified as a Cross-Site Scripting (XSS) vulnerability.
Is there a patch available for CVE-2026-39933?
Yes, a patch for CVE-2026-39933 has been implemented in the master branch of the GlobalWatchlist extension.