CVE-2025-32071

Severity CVSS v4.0:
CRITICAL
Type:
CWE-20 Input Validation
Publication date:
11/04/2025
Last modified:
15/04/2025

Description

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.