Starcitizen.Tools operates a narrowly scoped web-based utility supporting the Star Citizen game community, where its disclosed vulnerabilities concentrate in cross-site scripting weaknesses typical of web applications handling user input and content rendering. The recurring exposure reflects the inherent risks of interactive web platforms that aggregate or display user-generated or third-party data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Starcitizen.Tools over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-53370MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription extension ar | Jul 3, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-53368MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper | Jul 3, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-49576MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted | Jun 12, 2025 | 5.4 | 17 | NO | NO |
CVE-2025-49575MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody | Jun 12, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-47536MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves | Sep 30, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-36123MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascrip | Jun 3, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-49579MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, a | Jun 12, 2025 | 4.8 | 16 | NO | NO |
CVE-2025-49578MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybo | Jun 12, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-49577MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those mess | Jun 12, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Starcitizen.Tools.
Media articles that mention a CVE ID that affects a product developed by Starcitizen.Tools — matched by CVE ID, not by vendor name.