CVE-2025-61636 Details
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
A cross-site scripting (XSS) vulnerability has been identified in the Codex Special:Block interface of Wikimedia MediaWiki. This issue arises from improper handling of input in the HTMLButtonField program file, allowing message keys to be exploited. The vulnerability affects MediaWiki versions prior to 1.39.14, as well as 1.43.4 and 1.44.1.
Users can update to MediaWiki versions 1.39.14, 1.43.4, or 1.44.1, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://phabricator.wikimedia.org/T394396 | wikimedia-foundation | Issue TrackingThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | wikimedia-foundation |
Affected Products
| Product | Versions |
|---|---|
| mediawiki mediawiki | < 1.39.14 >= 1.39.15, < 1.43.4 >= 1.43.5, < 1.44.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 16, 2026 | Initial Analysis | [email protected] |
| Feb 3, 2026 | New CVE Received | wikimedia-foundation |