CVE-2026-103437
Received Received - Intake

Reflected XSS in MediaWiki ReadingLists Extension

Vulnerability report for CVE-2026-103437, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: wikimedia-foundation

Description

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
the_wikimedia_foundation mediawiki_readinglists_extension 1.46
the_wikimedia_foundation mediawiki_readinglists_extension 1.45

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected Cross-Site Scripting (XSS) vulnerability in the MediaWiki ReadingLists extension. It occurs when importing reading lists from external sources. The extension accepts an attacker-controlled project URL and uses the canonical URL returned by that server as a card link without validating its scheme. When a user opens a specially crafted URL and clicks the imported card, it executes attacker-supplied JavaScript in the wiki's origin.

Detection Guidance

To detect this vulnerability, monitor for unusual JavaScript execution in MediaWiki ReadingLists pages. Check server logs for requests to Special:ReadingLists with external URLs. Use browser developer tools to inspect network requests when importing reading lists.

Impact Analysis

The injected JavaScript runs with the victim's MediaWiki session privileges. This allows it to read same-origin data and perform actions on behalf of the user. The exploit requires a named user to open the link and activate the imported card.

Mitigation Strategies

Update MediaWiki ReadingLists extension to the patched version. Validate all imported URLs to ensure only HTTP(S) schemes are allowed. Restrict project validation to trusted Wikipedia subdomains. Review and remove any imported reading lists from untrusted sources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart