CVE-2025-7363

CVE-2025-7363: TitleIcon: Stored Cross-Site Scripting (XSS) via #titleicon_unicode parser function

Vendor Wikimedia Foundation
Product Mediawiki - TitleIcon extension
Weakness CWE-79 · XSS
Published July 8, 2025
Last update July 10, 2025

CVSS base score

What the vulnerability does

01Description

The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript. This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

Key dates

02Disclosure timeline

July 8, 2025 CVE published
July 10, 2025 Record updated