CVE-2026-57440: Starcitizenwiki Mediawiki-Extensions-Embedvideo
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escaped via double quotes, allowing for html/javascript injection. Version 4.1.0 contains a patch.
Affected products
- Starcitizenwiki Mediawiki-Extensions-Embedvideo: before 4.1.0 (fixed in 4.1.0)
Published 2026-09-24. Last modified 2026-09-30.