CVE-2026-58035: Stored XSS through a system message in the codex version of Special:Block
Published Jul 1, 2026
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue.
Affected Software
2 affected components
Wikimedia Foundation MediaWiki
MediaWiki MediaWiki=1.46.0-rc0
Event History
Jul 1, 2026
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58035?
The severity of CVE-2026-58035 is low, with a CVSS score of 4.0.
2
What type of vulnerability is associated with CVE-2026-58035?
CVE-2026-58035 is a Stored Cross-Site Scripting (XSS) vulnerability in Wikimedia Foundation MediaWiki.
3
How do I fix CVE-2026-58035?
To fix CVE-2026-58035, ensure proper input validation and sanitization in system message handling.
4
What software is affected by CVE-2026-58035?
CVE-2026-58035 affects the Wikimedia Foundation MediaWiki software.
5
Where in the code is CVE-2026-58035 located?
CVE-2026-58035 is associated with the program files in resources/src/mediawiki.Special.Block/SpecialBlock.Vue.