{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-24T07:37:33.192","vulnerabilities":[{"cve":{"id":"CVE-2025-53486","sourceIdentifier":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc","published":"2025-07-07T15:15:27.947","lastModified":"2026-06-17T09:38:18.030","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly concatenated into inline HTML without escaping. An attacker can inject JavaScript event handlers such as onmouseenter using carefully crafted input via the {{#tag:tagcloud}} parser function, resulting in arbitrary JavaScript execution when a victim hovers over a link in the category cloud.\n\n\n\n\nThe vulnerability exists because the linkstyle parameter is only passed through Sanitizer::checkCss() (which does not escape HTML) and is then directly inserted into a style attribute using string concatenation instead of Html::element or Html::openElement.\n\n\n\n\nThis issue affects Mediawiki - WikiCategoryTagCloud extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2."},{"lang":"es","value":"La extensión WikiCategoryTagCloud es vulnerable a XSS reflejado a través del atributo linkstyle, que se concatena incorrectamente en HTML en línea sin escape. Un atacante puede inyectar controladores de eventos JavaScript como \"onmouseenter\" utilizando una entrada cuidadosamente manipulada mediante la función de análisis {{#tag:tagcloud}}, lo que provoca la ejecución arbitraria de JavaScript al pasar el cursor sobre un enlace en la nube de categorías. La vulnerabilidad existe porque el parámetro linkstyle solo se pasa a través de Sanitizer::checkCss() (que no escapa HTML) y luego se inserta directamente en un atributo style mediante concatenación de cadenas en lugar de Html::element o Html::openElement. Este problema afecta a Mediawiki - extensión WikiCategoryTagCloud: de la versión 1.39.X a la 1.39.13, de la versión 1.42.X a la 1.42.7 y de la versión 1.43.X a la 1.43.2."}],"affected":[{"source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc","affectedData":[{"vendor":"Wikimedia Foundation","product":"Mediawiki - WikiCategoryTagCloud extension","defaultStatus":"unaffected","versions":[{"version":"1.39.x","lessThan":"1.39.13","versionType":"semver","status":"affected"},{"version":"1.42.x","lessThan":"1.42.7","versionType":"semver","status":"affected"},{"version":"1.43.x","lessThan":"1.43.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-07T19:13:04.719962Z","id":"CVE-2025-53486","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://gerrit.wikimedia.org/r/q/Idd68cf2372aedd916687d30b1bd09ebb48fcfd17","source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"},{"url":"https://phabricator.wikimedia.org/T394590","source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"}]}}]}