5.4
CVE-2025-32073 - System message XSS in HTMLTags
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediawiki - HTML Tags: from 1.39 through 1.43.
5.4
CVE-2025-32074 - XSSes in Extension:ConfirmAccount
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Confirm Account Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Confirm Account Extension: from 1.39 through 1.43.
6.9
CVE-2025-32075 - IP and user agent leaks in Extension:Tabs
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Tabs Extension allows Code Injection.This issue affects Mediawiki - Tabs Extension: from 1.39 through 1.43.
5.4
CVE-2025-32067 - i18n XSS vulnerability in message growthexperiments
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Growth Experiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Growth Experiments Extension: from 1.39 through 1.43.
5.4
CVE-2025-32068 - Revoking authorization of OAuth2 consumer does not invalidate refresh tokens
Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawiki - OAuth Extension: from 1.39 through 1.43.
5.4
CVE-2025-32069 - Wikitext stored XSS on filepages due to dangerous WBMI serialization
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Media Info Extension: from 1.39 through 1.43.
5.4
CVE-2025-32070 - XSSes in AJAXPoll
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - AJAX Poll Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - AJAX Poll Extension: from 1.39 through 1.43.
5.4
CVE-2025-32071 - Wikibase CommonsInlineImageFormatter: i18n XSS
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS)Β from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.
6.9
CVE-2025-31935 - Subnet Solutions PowerSYSTEM Center Deserialization of Untrusted Data
Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, resulting in a denial-of-service condition.
0.0
CVE-2025-3524 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.