CVE-2026-22712: ApprovedRevs allows bypassing the inline CSS sanitizer
Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22712?
CVE-2026-22712 is classified as a medium severity vulnerability due to improper encoding or escaping of output.
How do I fix CVE-2026-22712?
To fix CVE-2026-22712, update the Mediawiki - ApprovedRevs Extension to version 1.46 or later.
What versions of Mediawiki - ApprovedRevs Extension are affected by CVE-2026-22712?
CVE-2026-22712 affects Mediawiki - ApprovedRevs Extension versions 1.39 to 1.45 inclusive.
What kind of vulnerability is CVE-2026-22712?
CVE-2026-22712 is an input data manipulation vulnerability due to improper encoding or escaping of output.
Who is responsible for addressing CVE-2026-22712?
The Wikimedia Foundation is responsible for addressing and providing fixes for CVE-2026-22712.