The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript.
This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 08 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript. This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
Title | TitleIcon: Stored Cross-Site Scripting (XSS) via #titleicon_unicode parser function | |
Weaknesses | CWE-79 | |
References |
|

Status: PUBLISHED
Assigner: wikimedia-foundation
Published: 2025-07-08T17:27:17.643Z
Updated: 2025-07-10T14:07:16.818Z
Reserved: 2025-07-08T17:18:06.701Z
Link: CVE-2025-7363

Updated: 2025-07-10T14:07:12.341Z

Status : Awaiting Analysis
Published: 2025-07-08T18:15:46.913
Modified: 2025-07-10T14:15:27.100
Link: CVE-2025-7363

No data.