Medium severity6.1NVD Advisory· Published Sep 27, 2020· Updated Jun 17, 2026
CVE-2020-25814
CVE-2020-25814
Description
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an tag (or it does not have a href attribute, or it's empty, etc.). The actual result is that the object contains an <a href ="javascript... that executes when clicked.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mediawiki/corePackagist | >= 1.31.0, < 1.31.9 | 1.31.9 |
mediawiki/corePackagist | >= 1.32.0, < 1.34.3 | 1.34.3 |
mediawiki/corePackagist | >= 1.35.0-rc.0, < 1.35.0 | 1.35.0 |
Affected products
4- osv-coords2 versions
< 1.31.10+ 1 more
- (no CPE)range: < 1.31.10
- (no CPE)range: >= 1.31.0, < 1.31.9
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-4vr7-m8p8-434hghsaADVISORY
- lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.htmlnvdMailing ListRelease NotesVendor AdvisoryWEB
- lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.htmlnvdMailing ListRelease NotesVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-25814ghsaADVISORY
- www.mediawiki.org/wiki/ResourceLoader/Core_modulesnvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2020-25814.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6ghsaWEB
- phabricator.wikimedia.org/T86738ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/nvd
News mentions
0No linked articles in our index yet.