Medium severity5.4NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026
CVE-2023-45360
CVE-2023-45360
Description
An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7<1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1+ 4 more
- (no CPE)range: <1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1
- cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*range: <1.35.12
- cpe:2.3:a:mediawiki:mediawiki:1.40.0:-:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.40.0:rc0:*:*:*:*:*:*
- (no CPE)
- Range: <1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1
Patches
Vulnerability mechanics
References
3- phabricator.wikimedia.org/T340221nvdExploitIssue TrackingPatchVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/nvd
News mentions
0No linked articles in our index yet.