MassMessage vulnerability

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

Published 14 Sep 2026Updated 14 Sep 20262 sources
CVSS 5.4

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.