Wikimedia Foundation CheckUser Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the CheckUser extension of Wikimedia Foundation. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be executed. The vulnerability affects CheckUser versions prior to the commit 795bf333272206a0189050d975e94b70eb7dc507.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

The vulnerability can be reproduced by injecting a script into a message key that is then displayed by the CheckUser User Info Card feature. This can be done by overriding group messages with a payload that includes JavaScript, such as an image tag with an 'onerror' event.

Remediation

A patch has been developed and applied to the affected version.

Added: Feb 3, 2026, 1:26 AM
Updated: Feb 3, 2026, 1:26 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
6.0
remediation
7.7
relevance
2.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.