CVE-2026-39933Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-08)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-07: 1Mentions · 2026-04-08: 3Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 204-0704-08
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-083
Disclosure2General1
Full discourse4 posts
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-39337 | CVSS 10.0 🔴 CVE-2026-39933 | CVSS 10.0 🔴 CVE-2026-23696 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑CVSS CVEs with minimal details and a generic link, without providing PoC, exploit, active use, or mitigation information.

    0001080
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39933 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension a… https://www.cve.org/CVERecord?id=CVE-2026-39933

    Post summary

    CVE‑2026‑39933 is a cross‑site scripting vulnerability in the Wikimedia Foundation MediaWiki GlobalWatchlist extension, with technical details disclosed but no proof‑of‑concept, exploit code, or patch information provided.

    00000150
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39933 Cross-Site Scripting Vulnerability in Wikimedia Foundation MediaW... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39933 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet only references CVE‑2026‑39933 and links to a vulnerability details page, offering no additional technical or exploit information.

    0000036
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39933: Multiple XSS vulnerabilities in ... CVSS 10.0 XSS with zero interaction requirements screams stored payload paradise - GlobalWatchlist just became every wi... https://zerodaysignal.com/vulnerability/CVE-2026-39933 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    An announcement of a high‑severity XSS vulnerability (CVE-2026-39933) with a CVSS score of 10.0; no PoC or exploit details are provided.

    0000069
    204 followersView on X

Explore more