Junglewise Threat Intelligence

CVE-2026-39935: Wikimedia MediaWiki CampaignEvents XSS in Special:EventDetails

CVE-2026-39935 · Severity: info · CVSS 6.9 · Published 2026-04-07

Vendors: Wikimedia Foundation.

Executive brief

A security vulnerability exists in the CampaignEvents extension for MediaWiki, a platform used to manage collaborative websites and wikis. The flaw allows for cross-site scripting (XSS), which could enable an attacker to execute malicious scripts in the browsers of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the CampaignEvents extension for MediaWiki. The issue stems from the 'EventContributionsPager' component failing to properly escape localized wiki names retrieved from system messages before displaying them on the 'Contributions' tab of the 'Special:EventDetails' page. An attacker could potentially inject malicious scripts through these localized names. The vulnerability was addressed by ensuring wiki names are escaped for display. The fix has been merged into the master branch and is included in versions 1.43.7, 1.44.4, and 1.45.2.

Affected products

  • The Wikimedia Foundation MediaWiki - CampaignEvents Extension 1.43.7, 1.44.4, 1.45.2, and master branch

Timeline

  • 2026-02-24: disclosed: Vulnerability reported and task created in Phabricator
  • 2026-03-13: patched: Fix merged into master branch
  • 2026-04-07: advisory: CVE-2026-39935 published

References