TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HTMLinto the DOM by inserting a payload into any allowed attribute of the `<tabber>` tag. Version 3.1.1 contains a patch for the bug.
History

Fri, 27 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 18:00:00 +0000

Type Values Removed Values Added
Description TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HTMLinto the DOM by inserting a payload into any allowed attribute of the `<tabber>` tag. Version 3.1.1 contains a patch for the bug.
Title TabberNeue vulnerable to Stored XSS through wikitext
Weaknesses CWE-79
CWE-80
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-27T17:43:24.107Z

Updated: 2025-06-27T17:56:37.678Z

Reserved: 2025-06-25T13:41:23.085Z

Link: CVE-2025-53093

cve-icon Vulnrichment

Updated: 2025-06-27T17:53:05.282Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-27T18:15:50.773

Modified: 2025-06-30T18:38:23.493

Link: CVE-2025-53093

cve-icon Redhat

No data.