Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55691

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to sprintf while constructing a figure element. A quote in the class value can terminate the class attribute and inject arbitrary HTML attributes or markup into the rendered page. A user able to edit a wiki page can store JavaScript that executes for visitors who render the affected content. This issue is fixed in version 4.1.0.

EPSS

Процентиль: 22%
0.00295
Низкий

8.6 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.6
github
3 месяца назад

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template

EPSS

Процентиль: 22%
0.00295
Низкий

8.6 High

CVSS3

Дефекты

CWE-79