CVE-2025-67477 is a Cross-site Scripting (XSS) vulnerability in Wikimedia Foundation MediaWiki, specifically affecting versions before 1.44.3 and 1.45.1, stemming from improper input neutralization in the ApiSandboxLayout.Js file. The CVSS 4.0 score is currently undefined, but its nature as an XSS vulnerability typically implies a medium to high severity, allowing for client-side script injection. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.44.0, < 1.44.3CPE matchmatch criteria | cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* | ||
1.45.0CPE matchmatch criteria | cpe:2.3:a:mediawiki:mediawiki:1.45.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.