Vulnerability Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.
Related Weaknesses (CWE)
References
- https://phabricator.wikimedia.org/T358689
- https://lists.debian.org/debian-lts-announce/2025/07/msg00012.html
FAQ
What is CVE-2025-3469?
CVE-2025-3469 is a documented vulnerability. Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files include...
How severe is CVE-2025-3469?
CVSS scoring is not yet available for CVE-2025-3469. Check NVD for updates.
Is there a patch for CVE-2025-3469?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.