{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T04:47:27.739","vulnerabilities":[{"cve":{"id":"CVE-2025-7363","sourceIdentifier":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc","published":"2025-07-08T18:15:46.913","lastModified":"2026-06-17T10:04:47.457","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript.\n\n\n\n\nThis issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2."},{"lang":"es","value":"La extensión TitleIcon para MediaWiki es vulnerable a XSS almacenado a través de la función de análisis #titleicon_unicode. La entrada del usuario enviada a esta función se encapsula en un objeto HtmlArmor sin depurar y se renderiza directamente en el encabezado de la página, lo que permite a los atacantes inyectar JavaScript arbitrario. Este problema afecta a Mediawiki - extensión TitleIcon: de la versión 1.39.X a la 1.39.13, de la versión 1.42.X a la 1.42.7 y de la versión 1.43.X a la 1.43.2."}],"affected":[{"source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc","affectedData":[{"vendor":"Wikimedia Foundation","product":"Mediawiki - TitleIcon extension","defaultStatus":"unaffected","versions":[{"version":"1.39.x","lessThan":"1.39.13","versionType":"semver","status":"affected"},{"version":"1.42.x","lessThan":"1.42.7","versionType":"semver","status":"affected"},{"version":"1.43.x","lessThan":"1.43.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-10T14:06:52.777733Z","id":"CVE-2025-7363","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://gerrit.wikimedia.org/r/q/I107ab638fecbf52b5bec3f02726ed24b1ae74429","source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"},{"url":"https://gerrit.wikimedia.org/r/q/I2e8c73445172679634f6ec64d37cf82507dfa110","source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"},{"url":"https://phabricator.wikimedia.org/T394721","source":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"},{"url":"https://phabricator.wikimedia.org/T394721","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}}]}