High severity8.6NVD Advisory· Published Jan 6, 2025· Updated Apr 15, 2026
CVE-2025-21612
CVE-2025-21612
Description
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
starcitizentools/tabber-neuePackagist | >= 1.9.1, < 2.7.2 | 2.7.2 |
Patches
2d8c3db4e5935f229cab099c6Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
5- github.com/advisories/GHSA-4x6x-8rm8-c37jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-21612ghsaADVISORY
- github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/commit/d8c3db4e5935476e496d979fb01f775d3d3282e6nvdWEB
- github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/commit/f229cab099c69006e25d4bad3579954e481dc566nvdWEB
- github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/security/advisories/GHSA-4x6x-8rm8-c37jnvdWEB
News mentions
0No linked articles in our index yet.