๐Ÿ” CVE Alert

CVE-2026-103437

UNKNOWN 0.0

ReadingLists imported metadata permits JavaScript URL XSS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.

CWE CWE-80
Vendor the wikimedia foundation
Product mediawiki readinglists extension
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for the wikimedia foundation mediawiki readinglists extension

Be the first to know when new unknown vulnerabilities affecting the wikimedia foundation mediawiki readinglists extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Wikimedia Foundation / MediaWiki ReadingLists extension
1.46 1.45

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T435863 gerrit.wikimedia.org: https://gerrit.wikimedia.org/r/q/I9a724c05b2a55845007512422362e02ed8cf44b0

Credits

๐Ÿ” Marco Paciaroni (BomboBombone)