CVE-2026-103437EPSS p20.9%
CVE-2026-103437CVE-2026-103437
Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS.
This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.
Scoring
| EPSS | 0.30% probability of exploitation · percentile 20.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |