PatchSiren cyber security CVE debrief
CVE-2026-96875 The Wikimedia Foundation CVE debrief
A cross-site scripting vulnerability in Mediawiki - Cargo extension allows Stored XSS, affecting versions through 3.9.4. Defenders should assess exposure and prioritize patching or mitigation. The vulnerability is caused by improper neutralization of input during web page generation. This issue has a CVSS score of 6.9 and is classified as MEDIUM severity. Verification of affected versions is required to prevent potential XSS attacks. Defenders should monitor for suspicious activity and apply patches or mitigations for vulnerable versions.
- Vendor
- The Wikimedia Foundation
- Product
- Mediawiki - Cargo extension
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for Mediawiki - Cargo extension deployments should assess exposure and prioritize patching or mitigation. This includes reviewing system logs for suspicious activity, verifying the integrity of web pages, and ensuring that all necessary security patches are applied. Additionally, defenders should educate users about the risks associated with this vulnerability and provide guidance on safe usage.
Why it matters
CVE-2026-96875 is a cross-site scripting vulnerability in Mediawiki - Cargo extension that allows Stored XSS. Defenders should prioritize verification of affected versions and apply patches or mitigations to prevent potential XSS attacks.
- Verification of affected versions is required
- Potential for XSS attacks if not patched
- Defenders should monitor for suspicious activity
Technical summary
The Mediawiki - Cargo extension is vulnerable to Stored XSS due to improper neutralization of input during web page generation. This vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Defenders should prioritize verification of affected versions and apply patches or mitigations to prevent potential XSS attacks.
Defensive priority
Defenders should prioritize verification of affected versions and apply patches or mitigations.
Recommended defensive actions
- Verify affected versions of Mediawiki - Cargo extension
- Apply patches or mitigations for vulnerable versions
- Monitor for potential XSS attacks
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The CVE record was published on 2026-09-25T20:17:47.800Z and has not been modified since then. The NVD entry also provides limited information about the vulnerability. Defenders should verify the affected versions and apply patches or mitigations to prevent potential XSS attacks. The vulnerability affects Mediawiki - Cargo extension versions through 3.9.4.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96875 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96875
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96875 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96875
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://phabricator.wikimedia.org/T435206
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.