CVE-2025-61648 – Stored XSS through system messages in CheckUser

CVE ID : CVE-2025-61648

Published : Feb. 3, 2026, 12:19 a.m. | 57 minutes ago

Description : Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/ShowIPButton.Vue, modules/ext.CheckUser.TempAccounts/SpecialBlock.Js.

This issue affects CheckUser: from * before 1.44.1.

Severity: 0.0 | NONE

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه