CVE-2026-58037: Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Language/Language.Php, includes/Logging/BlockLogFormatter.Php, includes/Logging/LogFormatter.Php, includes/Logging/PatrolLogFormatter.Php, includes/Logging/RenameuserLogFormatter.Php, includes/Logging/TagLogFormatter.Php, includes/Specials/SpecialVersion.Php.
This issue affects MediaWiki: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MediaWikito a version that resolves this vulnerability.Fixed in 1.46.0 - Upgrade
Upgrade
MediaWikito a version that resolves this vulnerability.Fixed in 1.45.4 - Upgrade
Upgrade
MediaWikito a version that resolves this vulnerability.Fixed in 1.44.6 - Upgrade
Upgrade
MediaWikito a version that resolves this vulnerability.Fixed in 1.43.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58037?
CVE-2026-58037 has a low severity rating of 0.
What type of vulnerability is identified in CVE-2026-58037?
CVE-2026-58037 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-site Scripting (XSS).
How do I fix CVE-2026-58037?
To fix CVE-2026-58037, ensure proper input validation and sanitization to prevent XSS vulnerabilities in log entry formatting code.
What software is affected by CVE-2026-58037?
CVE-2026-58037 affects the Wikimedia Foundation MediaWiki software.
When was CVE-2026-58037 published?
CVE-2026-58037 was published on July 1, 2026.