CVE-2026-39936: Stored XSS in Score due to usage of non-reserved data attributes
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the master branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39936?
CVE-2026-39936 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2026-39936?
To fix CVE-2026-39936, update the Mediawiki Score Extension to the latest version where the XSS vulnerability has been remediated.
What software is affected by CVE-2026-39936?
CVE-2026-39936 affects the Mediawiki Score Extension used by The Wikimedia Foundation.
What type of vulnerability is CVE-2026-39936?
CVE-2026-39936 is a stored cross-site scripting (XSS) vulnerability caused by improper neutralization of input.
Can CVE-2026-39936 be exploited remotely?
Yes, CVE-2026-39936 can be exploited remotely by injecting malicious scripts through non-reserved data attributes.