The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript. This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00026}

epss

{'score': 0.00029}


Thu, 10 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
Description The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript. This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Title TitleIcon: Stored Cross-Site Scripting (XSS) via #titleicon_unicode parser function
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published: 2025-07-08T17:27:17.643Z

Updated: 2025-07-10T14:07:16.818Z

Reserved: 2025-07-08T17:18:06.701Z

Link: CVE-2025-7363

cve-icon Vulnrichment

Updated: 2025-07-10T14:07:12.341Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T18:15:46.913

Modified: 2025-07-10T14:15:27.100

Link: CVE-2025-7363

cve-icon Redhat

No data.