The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript.
This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 08 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript. This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
| Title | TitleIcon: Stored Cross-Site Scripting (XSS) via #titleicon_unicode parser function | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: wikimedia-foundation
Published: 2025-07-08T17:27:17.643Z
Updated: 2025-07-10T14:07:16.818Z
Reserved: 2025-07-08T17:18:06.701Z
Link: CVE-2025-7363
Updated: 2025-07-10T14:07:12.341Z
Status : Awaiting Analysis
Published: 2025-07-08T18:15:46.913
Modified: 2025-07-10T14:15:27.100
Link: CVE-2025-7363
No data.