216.73.217.22

CVE-2025-32072

· Published 11/04/2025 17:15 · Modified 11/04/2025 17:15

Labels: CVE-2025-32072 2025-04-11CVE-2025-32072CWE-116c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

Essential information

Published
11/04/2025 17:15
Modified
11/04/2025 17:15
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
NVD
View on NVD

Affected products (CPE)

ProductCPE
wikimedia / mediawiki cpe:2.3:a:wikimedia:mediawiki:1.39:*:*:*:*:*:*:*
wikimedia / mediawiki cpe:2.3:a:wikimedia:mediawiki:1.40:*:*:*:*:*:*:*
wikimedia / mediawiki cpe:2.3:a:wikimedia:mediawiki:1.41:*:*:*:*:*:*:*
wikimedia / mediawiki cpe:2.3:a:wikimedia:mediawiki:1.42:*:*:*:*:*:*:*
wikimedia / mediawiki cpe:2.3:a:wikimedia:mediawiki:1.43:*:*:*:*:*:*:*

References