CVE-2026-39935: XSS-via-i18n in localised wiki names
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the master branch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39935?
CVE-2026-39935 has been classified with a high severity due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2026-39935?
To fix CVE-2026-39935, update to the latest version of the Wikimedia Foundation CampaignEvents Extension available on the master branch.
What systems are affected by CVE-2026-39935?
CVE-2026-39935 affects the Wikimedia Foundation CampaignEvents Extension specifically.
What is Cross-Site Scripting as it relates to CVE-2026-39935?
Cross-Site Scripting in CVE-2026-39935 refers to the improper neutralization of input that allows malicious scripts to be executed in users' browsers.
How was CVE-2026-39935 remediated?
CVE-2026-39935 was remediated by implementing input sanitization measures in the master branch of the Wikimedia Foundation CampaignEvents Extension.