CVE-2025-6591 Details
Description
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiFeedContributions.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7 1.43.2, 1.44.0.
A vulnerability allowing HTML injection has been identified in the Wikimedia Foundation MediaWiki API, specifically within the 'feedcontributions' action of the 'ApiFeedContributions' class. This issue affects MediaWiki versions prior to 1.39.13, as well as 1.42.7, 1.43.2, and 1.44.0. The vulnerability arises because internationalization (i18n) messages are not properly escaped before being outputted, potentially allowing for the injection of unescaped script tags into the feed contributions API response.
The vulnerability has been addressed in MediaWiki versions 1.39.13, 1.42.7, 1.43.2, and 1.44.0. Users should update to one of these versions to mitigate the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 2, 2026CISA-ADP
Assessed Feb 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://phabricator.wikimedia.org/T392276 | wikimedia-foundation | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Wikimedia Foundation MediaWiki | < 1.39.13 (semver) < 1.42.7 (semver) < 1.43.2 (semver) < 1.44.0 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 28, 2026 | CVE Modified | CISA-ADP |
| Feb 4, 2026 | CVE Modified | CISA-ADP |
| Feb 2, 2026 | New CVE Received | wikimedia-foundation |
Volerion