CVE-2023-22910: Mediawiki
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have the editsitejs capability.
Affected products
- Mediawiki Mediawiki: before 1.35.9 (fixed in 1.35.9); from 1.36.0, before 1.38.5 (fixed in 1.38.5); version 1.39.0 only
Published 2023-01-20. Last modified 2026-06-17.