CVE-2026-58030: SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation SyntaxHighlightGeSHi.
This vulnerability is associated with program files includes/SyntaxHighlight.Php.
This issue affects SyntaxHighlightGeSHi: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58030?
The severity of CVE-2026-58030 is classified as medium with a CVSS score of 5.3.
What type of vulnerability is CVE-2026-58030?
CVE-2026-58030 is a stored XSS (Cross-site Scripting) vulnerability due to improper neutralization of input.
Which software is affected by CVE-2026-58030?
CVE-2026-58030 affects the Wikimedia Foundation's SyntaxHighlight_GeSHi software prior to version 1.46.0.
How can I fix CVE-2026-58030?
To fix CVE-2026-58030, update to the latest version of SyntaxHighlight_GeSHi to ensure input sanitization.
What is the impact of CVE-2026-58030?
Exploitation of CVE-2026-58030 can lead to unauthorized execution of malicious scripts in the context of affected web pages.