VYPR

TitleIcon

by MediaWiki

CVEs (1)

  • CVE-2025-7363MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject…