CVE-2020-27620: Mediawiki Skin:cosmos

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.

Affected products

  • Mediawiki Skin:cosmos: up to and including 1.35.0

Published 2020-10-22. Last modified 2026-06-17.