CVE-2025-53369 is a high-severity vulnerability in the MediaWiki Short Description extension (version 4.0.0) that allows any user to inject arbitrary HTML into the DOM through unsanitized short descriptions. This flaw, categorized as CWE-79 (Improper Neutralization of Input During Web Page Generation), carries a CVSS score of 8.6, indicating a critical risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, with moderate impact on integrity and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability has been patched in version 4.0.1 of the extension.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| StarCitizenTools | Mediawiki-Extensions-ShortDescription | >= 05f6c6824f8f37dcc2d51cf6df4e7a09bea2196c, < 2c18bd21c5de53c336f55b6ff42f2983ea5796b4, >= 4.0.0, < 4.0.1CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.