CVE-2025-21612: Starcitizentools Mediawiki-Extensions-Tabberneue

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.

Affected products

  • Starcitizentools Mediawiki-Extensions-Tabberneue: from 1.9.1, before 2.7.2 (fixed in 2.7.2); from d8c3db4e5935476e496d979fb01f775d3d3282e6, before f229cab099c69006e25d4bad3579954e481dc566 (fixed in f229cab099c69006e25d4bad3579954e481dc566)

Published 2025-01-06. Last modified 2026-06-17.