Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20238 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Quiz Extension allows Stored XSS.This issue affects Mediawiki - Quiz Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. |
Mon, 07 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 07 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Quiz Extension allows Stored XSS.This issue affects Mediawiki - Quiz Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
| Title | Stored XSS in Quiz | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2025-07-10T23:22:18.817Z
Reserved: 2025-07-03T22:11:35.744Z
Link: CVE-2025-7057
Updated: 2025-07-07T19:14:22.114Z
Status : Deferred
Published: 2025-07-07T16:15:26.123
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-7057
No data.
OpenCVE Enrichment
Updated: 2025-07-13T22:31:27Z
EUVD