VYPR

MsUpload

by MediaWiki

CVEs (1)

  • CVE-2025-7362MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted into the DOM without proper sanitization. The vulnerability occurs in the file upload UI when the same filename is uploaded twice. This issue affects…