CVE-2026-0671

CVE-2026-0671: Multiple stored i18n/message-key XSSes in UploadWizard

Vendor Wikimedia Foundation
Product MediaWiki - UploadWizard extension
Weakness CWE-79 · XSS
Published January 8, 2026
Last update January 8, 2026

CVSS base score

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39.

Key dates

02Disclosure timeline

January 8, 2026 CVE published
January 8, 2026 Record updated