Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2mp-vfg6-8xwm

Опубликовано: 08 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: 1.43.7, 1.44.4, 1.45.2.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: 1.43.7, 1.44.4, 1.45.2.

EPSS

Процентиль: 15%
0.00047
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
5 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch.

EPSS

Процентиль: 15%
0.00047
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-79