CVE-2026-39935

Publication date

2026-04-07 22:04:02

Family

wikimedia-foundation

State

PUBLISHED

Description

Improper neutralization of input during web page generation (cross-site scripting) vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: 1.43.7, 1.44.4, 1.45.2.