CVE-2026-22712
Unknown
Unknown - Not Provided
Improper Output Encoding in Mediawiki ApprovedRevs Enables Data Manipulation
Publication date: 2026-01-09
Last updated on: 2026-02-12
Assigner: wikimedia-foundation
Description
Description
Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wikiworks | approved_revs | 1.39 |
| wikiworks | approved_revs | 1.43 |
| wikiworks | approved_revs | 1.44 |
| wikiworks | approved_revs | 1.45 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-116 | The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved. |