๐Ÿ” CVE Alert

CVE-2026-103445

UNKNOWN 0.0

Stored XSS through PageForms #autoedit redirect links

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.

CWE CWE-80
Vendor the wikimedia foundation
Product mediawiki page_forms extension
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for the wikimedia foundation mediawiki page_forms extension

Be the first to know when new unknown vulnerabilities affecting the wikimedia foundation mediawiki page_forms extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Wikimedia Foundation / MediaWiki Page_Forms extension
1.46 1.45 1.43

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T435622 gerrit.wikimedia.org: https://gerrit.wikimedia.org/r/q/I4ace525a1c1760ecdd1d770380606d9960d3e644

Credits

๐Ÿ” Marco Paciaroni (BomboBombone)