Medium severity6.1NVD Advisory· Published Dec 11, 2019· Updated Jun 17, 2026
CVE-2019-19708
CVE-2019-19708
Description
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mediawiki:visual_editor:*:*:*:*:*:mediawiki:*:*+ 1 more
- cpe:2.3:a:mediawiki:visual_editor:*:*:*:*:*:mediawiki:*:*range: <=1.34
- (no CPE)range: <=1.34
- MediaWiki/VisualEditor extensiondescription
Patches
Vulnerability mechanics
References
2- gerrit.wikimedia.org/r/q/I1f99458fd2c4f6b2460dfe7a93b330ddee4400b6nvdExploitVendor Advisory
- phabricator.wikimedia.org/T239209nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.