CVE-2025-6596 is a Cross-site Scripting (XSS) vulnerability affecting Wikimedia Foundation Vector versions 1.40.0 through 1.42.7, 1.43.2, and 1.44.0, specifically within the portlets.Js program files. The CVSS score is 0.0, indicating no defined severity metrics, but the CWE-79 classification points to improper neutralization of input during web page generation. While the FAUCET Risk Score is 15/100, suggesting a low overall risk, the lack of detailed CVSS metrics makes a precise severity assessment difficult. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wikimedia Foundation | Vector | >= >= 1.40.0, < 1.42.7, 1.43.2, 1.44.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.