CVE-2026-0671
EUVD-2026-144808.01.2026, 17:15
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wikimedia | mediawiki-extensions-uploadwizard | 1.39 |
| wikimedia | mediawiki-extensions-uploadwizard | 1.43 |
| wikimedia | mediawiki-extensions-uploadwizard | 1.44 |
| wikimedia | mediawiki-extensions-uploadwizard | 1.45 |
𝑥
= Vulnerable software versions