CVE-2025-32071

Publication date

2025-04-11 16:19:46

Family

wikimedia-foundation

State

PUBLISHED

Description

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.