<Vulnerability name="CVE-2026-58031">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-01T14:24:21</PublicDate>
    <Bugzilla id="2495993" url="https://bugzilla.redhat.com/show_bug.cgi?id=2495993" xml:lang="en:us">
MediaWiki: MediaWiki: Cross-site scripting vulnerability due to improper input neutralization
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>4.6</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-79</CWE>
    <Details xml:lang="en:us" source="Mitre">
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki.

 This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js.



This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Wikimedia Foundation MediaWiki. This vulnerability, categorized as an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting or XSS), allows a remote attacker to inject malicious scripts into web pages. When a user views an affected page, the attacker's script can execute in their browser, potentially leading to information disclosure, session hijacking, or defacement of the website.
    </Details>
    <Statement xml:lang="en:us">
Moderate: A cross-site scripting (XSS) vulnerability in MediaWiki allows a remote attacker to inject malicious scripts into web pages. When a user views an affected page, the attacker's script can execute in their browser, potentially leading to information disclosure or session hijacking. This flaw specifically affects the ApiSandboxLayout.Js component, which is part of the MediaWiki application.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-58031
https://nvd.nist.gov/vuln/detail/CVE-2026-58031
https://phabricator.wikimedia.org/T426889
    </References>
</Vulnerability>