CVE-2024-23176: Mediawiki Massmessage

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

Affected products

  • Mediawiki Massmessage: before 1.40.2 (fixed in 1.40.2)

Published 2026-09-14. Last modified 2026-09-28.