CVE-2026-39837: Stored XSS through the dynamic table format in Cargo
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39837?
CVE-2026-39837 is considered a high-severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2026-39837?
To fix CVE-2026-39837, update the MediaWiki Cargo Extension to version 3.8.7 or later.
What is stored XSS in the context of CVE-2026-39837?
Stored XSS in the context of CVE-2026-39837 occurs when malicious scripts are injected into a web page and stored on the server, affecting users who later access that page.
Which versions of MediaWiki Cargo Extension are affected by CVE-2026-39837?
CVE-2026-39837 affects MediaWiki Cargo Extension versions prior to 3.8.7.
Can CVE-2026-39837 impact user data security?
Yes, CVE-2026-39837 can compromise user data security by allowing attackers to execute malicious scripts in the context of the user's session.