PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96875 The Wikimedia Foundation CVE debrief

A cross-site scripting vulnerability in Mediawiki - Cargo extension allows Stored XSS, affecting versions through 3.9.4. Defenders should assess exposure and prioritize patching or mitigation. The vulnerability is caused by improper neutralization of input during web page generation. This issue has a CVSS score of 6.9 and is classified as MEDIUM severity. Verification of affected versions is required to prevent potential XSS attacks. Defenders should monitor for suspicious activity and apply patches or mitigations for vulnerable versions.

Vendor
The Wikimedia Foundation
Product
Mediawiki - Cargo extension
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Mediawiki - Cargo extension deployments should assess exposure and prioritize patching or mitigation. This includes reviewing system logs for suspicious activity, verifying the integrity of web pages, and ensuring that all necessary security patches are applied. Additionally, defenders should educate users about the risks associated with this vulnerability and provide guidance on safe usage.

Why it matters

CVE-2026-96875 is a cross-site scripting vulnerability in Mediawiki - Cargo extension that allows Stored XSS. Defenders should prioritize verification of affected versions and apply patches or mitigations to prevent potential XSS attacks.

  • Verification of affected versions is required
  • Potential for XSS attacks if not patched
  • Defenders should monitor for suspicious activity

Technical summary

The Mediawiki - Cargo extension is vulnerable to Stored XSS due to improper neutralization of input during web page generation. This vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Defenders should prioritize verification of affected versions and apply patches or mitigations to prevent potential XSS attacks.

Defensive priority

Defenders should prioritize verification of affected versions and apply patches or mitigations.

Recommended defensive actions

  • Verify affected versions of Mediawiki - Cargo extension
  • Apply patches or mitigations for vulnerable versions
  • Monitor for potential XSS attacks

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The CVE record was published on 2026-09-25T20:17:47.800Z and has not been modified since then. The NVD entry also provides limited information about the vulnerability. Defenders should verify the affected versions and apply patches or mitigations to prevent potential XSS attacks. The vulnerability affects Mediawiki - Cargo extension versions through 3.9.4.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96875 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96875

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96875 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96875

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://phabricator.wikimedia.org/T435206

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.