CVE-2026-96874Low· 2.3▾ SunlitImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 12.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS.
This issue affects Mediawiki - Cargo extension: through 3.9.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96876Medium· 6.9Anonymous reflected XSS in CargoExport invalid-alias errors
CVE-2026-96875Medium· 6.9Reflected XSS in Cargo Drilldown hierarchy filters
CVE-2026-96877Medium· 6.9Reflected XSS through Cargo Drilldown full-text search
CVE-2026-96878Medium· 6.9Cargo Exhibit field alias allows stored XSS
CVE-2026-100237Medium· 6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects Mediawiki - Thanks Extension: from * befor…
CVE-2026-96873Medium· 5.5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.