- Description
- Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 4.0.1.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.6
- Impact score
- 4.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- Severity
- HIGH
- security-advisories@github.com
- CWE-79
- Hype score
- Not currently trending
CVE-2025-53369 Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being… https://t.co/wgZ7zSBaV8
@CVEnew
3 Jul 2025
473 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-53369: HIGH] MediaWiki extension v4.0.0 vulnerability alert! Short descriptions are unsanitized allowing HTML injection. Update to v4.0.1 to patch this security flaw. #cybersecurity#cve,CVE-2025-53369,#cybersecurity https://t.co/zhFqgnB4DE https://t.co/formlNFuSm
@CveFindCom
3 Jul 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes