CVE-2026-57440

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escaped via double quotes, allowing for html/javascript injection. Version 4.1.0 contains a patch.

Published
September 24, 2026 7:17 PM
Last Modified
September 24, 2026 7:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-79 CWE-80

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.