{"id":"CVE-2025-62697","title":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - Lang…","summary":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - Lang…","severity":"none","cwe":["CWE-74"],"published":"2025-10-20","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:10:00.563","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-62697","references":[{"url":"https://gerrit.wikimedia.org/r/q/I338288e756de4e58a3f1f02a9c205b37f4927935","label":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"},{"url":"https://phabricator.wikimedia.org/T399724","label":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"}],"tags":["nvd"],"epss":0.00347,"epssPercentile":0.26172,"ingestedAt":"2026-10-08T22:11:53.823Z","slug":"CVE-2025-62697","body":"## Overview\n\nImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before 1.39.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}