Wikimedia Parsoid vulnerabilities
2 known vulnerabilities affecting wikimedia/parsoid.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-61638UNKNOWNCVSS 0.0fixed in 0.16.6fixed in 0.20.4+1 more2026-02-03
CVE-2025-61638 [NONE] CWE-79 CVE-2025-61638: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php.
This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoi
nvd
CVE-2021-30458MEDIUMCVSS 6.1fixed in 0.11.1≥ 0.12.0, < 0.12.22021-04-09
CVE-2021-30458 [MEDIUM] CWE-79 CVE-2021-30458: An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a tag, bypassing sanitization steps, and potentially allowing for XSS.
ghsanvdosv