MassMessage vulnerability

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

Published 14 Sep 2026Updated 14 Sep 20262 sources
CVSS 5.4

Source timeline

CVE record published by NVDView source ↗