← Back to CVE List

CVE-2025-21612

Published: 2025-01-06T16:15Z
Last Modified: 2025-01-06T17:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt