CVE-2025-6595
Publication date 2 February 2026
Last updated 4 February 2026
Ubuntu priority
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mediawiki | 25.10 questing |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2025-6595
- https://lists.wikimedia.org/hyperkitty/list/[email protected]/thread/TT45WDZ7MDTXXBEFLBMLAJI532O2PN2U/
- https://phabricator.wikimedia.org/T394863
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/MultimediaViewer/+/1165106 (master)
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/MultimediaViewer/+/1165144 (REL1_39)