PULSE
FEED
ransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technologyransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technology
← All CVEs
CVE WatchSep 30, 2026

CVE-2026-103050

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - M

CVSS

—

No CVSS

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-79

EPSS · 30d

Not enough EPSS history yet.

Technical description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-966497.2 HIG
—
———The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode.10h
CVE-2026-1028474.3 MED
—
———A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component Guest Book. This manipulation of the argument nama/email/pesan causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.11h
CVE-2026-103051—
—
——0Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10.13h
CVE-2026-103049—
—
——0Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: before 1.46.1.13h
CVE-2026-103047—
—
——0Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10.14h
CVE-2026-103046—
—
——0Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki - WikiLambda extension: before 1.46.1.14h