Security Advisory

CVE-2025-32071

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-11 16:19:46
Last updated 2025-07-07 14:17:52
Assigner wikimedia-foundation
State PUBLISHED

Description

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.