CVE-2025-61650 Details
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Services/CheckUserUserInfoCardService.Php. This issue affects CheckUser: from * before 795bf333272206a0189050d975e94b70eb7dc507.
A stored cross-site scripting vulnerability has been identified in the CheckUser extension of Wikimedia Foundation. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be executed. The vulnerability affects CheckUser versions prior to the commit 795bf333272206a0189050d975e94b70eb7dc507.
A patch has been developed and applied to the affected version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 3, 2026CISA-ADP
Assessed Feb 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://phabricator.wikimedia.org/T403289 | wikimedia-foundation | ExploitIssue TrackingRemedyTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | wikimedia-foundation |
Affected Products
| Product | Versions |
|---|---|
| Wikimedia Foundation CheckUser | < 795bf333272206a0189050d975e94b70eb7dc507 |
CPE
Remediation | |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2026 | New CVE Received | wikimedia-foundation |
Volerion