{"id":"CVE-2019-12471","aliases":["GHSA-2rm7-xxx8-35jh"],"url":"https://o3.security/vulnerability/CVE-2019-12471","summary":"MediaWiki Cross-site Scripting (XSS)","details":"Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.","published":"2019-07-10T16:15:11.150Z","modified":"2026-07-08T05:54:49.507507474Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.01522,"percentile":0.72256,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mediawiki/core","fixedVersion":"1.27.6"},{"ecosystem":"Packagist","name":"mediawiki/core","fixedVersion":"1.30.2"},{"ecosystem":"Packagist","name":"mediawiki/core","fixedVersion":"1.31.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://phabricator.wikimedia.org/T207603"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jun/12"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4460"},{"type":"FIX","url":"https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:54:49.507507474Z"}}