CVE-2026-58031: Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected
Published Jul 1, 2026
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js.
This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0.
Affected Software
2 affected components
Wikimedia Foundation MediaWiki>1.46.0-rc.0<=1.46.0
MediaWiki MediaWiki=1.46.0-rc0
Event History
Jul 1, 2026
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58031?
CVE-2026-58031 has a low severity rating with a CVSS score of 4.0.
2
How do I fix CVE-2026-58031?
To mitigate CVE-2026-58031, update your MediaWiki installation to the latest version.
3
What type of vulnerability is CVE-2026-58031?
CVE-2026-58031 is categorized as a stored XSS (Cross-site Scripting) vulnerability.
4
Which software is affected by CVE-2026-58031?
CVE-2026-58031 affects the MediaWiki software from version 1.46.0 onward.
5
Where can I find more information about CVE-2026-58031?
Additional details regarding CVE-2026-58031 can be found in the related issue on Wikimedia's Phabricator.