Security Advisory

CVE-2026-39935

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-07 22:04:02
Last updated 2026-04-08 22:06:48
Assigner wikimedia-foundation
State PUBLISHED

Description

Improper neutralization of input during web page generation (cross-site scripting) vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch.