CVE-2026-103046 - WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML
CVE ID :CVE-2026-103046
Published : Sept. 29, 2026, 10:41 p.m. | 31 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki - WikiLambda extension: before 1.46.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 29, 2026, 10:41 p.m. | 31 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki - WikiLambda extension: before 1.46.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...