VYPR
Medium severity5.3NVD Advisory· Published Jan 14, 2025· Updated Jun 17, 2026

CVE-2025-23080

CVE-2025-23080

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - OpenBadges Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • >=1.39.0,<1.39.11 || >=1.41.0,<1.41.3 || >=1.42.0,<1.42.2+ 1 more
    • (no CPE)range: >=1.39.0,<1.39.11 || >=1.41.0,<1.41.3 || >=1.42.0,<1.42.2
    • (no CPE)range: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2
  • Range: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.