CVE-2026-39933

Publication date

2026-04-07 21:51:55

Family

wikimedia-foundation

State

PUBLISHED

Description

Improper neutralization of input during web page generation (cross-site scripting) vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension allows Cross-Site Scripting (XSS).This issue affects non release branches.