Page MenuHomePhabricator

Write and send supplementary release announcement for extensions and skins with security patches (1.39.14/1.43.4/1.44.1)
Closed, ResolvedPublic

Description

This release is now locked! Please use T404620 for any future, non-core security-issue tracking.

Previous work: T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2)

Issue IDExtension or SkinCVE IDREL1_39REL1_43REL1_44master/main
T397521LockdownCVE-2025-12004N/AYesYesYes
GHSA-gvfx-p3h5-qf65DiscordNotificationsCVE-2025-53371N/AN/AN/AYes
GHSA-7pgw-q3qp-6pgqDynamicPageList3CVE-2025-53625N/AN/AN/AYes
T399583LastModifiedCVE-2025-62693YesYesYesYes
T399658MultiBoilerplateCVE-2025-62700YesYesYesYes
T399662ExternalGuidanceCVE-2025-62698YesYesYesYes
T399724LanguageSelectorCVE-2025-62697YesYesYesYes
T399627TranslateCVE-2025-62699NoNoYesYes
T399627TranslateCVE-2025-62699NoNoYesYes
T400422SpringboardCVE-2025-62696N/AN/AN/AYes
T400500WikiLambdaCVE-2025-62695NoNoNoYes
T400525WikiLoveCVE-2025-62694YesYesYesYes
T400526PageTriageCVE-2025-62702N/AN/AYesYes
T400545WikistoriesCVE-2025-62701N/AYesYesYes
T401046BlueSkyCVE-2025-62665YesYesYesYes
GHSA-hqfr-7cm9-4h87TilesheetsCVE-2025-54865N/AN/AN/AYes
T402002ImageRatingCVE-2025-62664YesYesYesYes
T402076SecurePollCVE-2025-11937N/AN/AN/AYes
T402095UploadWizardCVE-2025-62663N/AYesYesYes
T402146AdvancedSearchCVE-2025-62662YesYesYesYes
T402147CargoCVE-2025-62671N/AN/AN/AYes
T402149FlexDiagramsCVE-2025-62670N/AN/AN/AYes
T397497ThanksCVE-2025-62661NoYesYesYes
T397497GrowthExperimentsCVE-2025-62661NoNoNoYes
T400892CentralAuthCVE-2025-62669NoYesYesYes
T402600GrowthExperimentsCVE-2025-62668YesYesYesYes
T402698GrowthExperimentsCVE-2025-62667YesYesYesYes
T401220CirrusSearchCVE-2025-62666NoYesYesYes
T403093WebAuthnCVE-2025-62652YesYesYesYes
T403923PollNYCVE-2025-62653YesYesYesYes
T403924QuizGameCVE-2025-62654YesYesYesYes
GHSA-f2rp-232x-mqrh3DAlloyCVE-2025-59332N/AN/AN/AYes
T404016CargoCVE-2025-62655YesYesYesYes
T404392 1WikiLambdaN/AN/AN/AN/AYes
T404392 2WikiLambdaN/AN/AN/AN/AYes
T404475CookieConsentCVE-2025-62659N/AN/AN/AYes
T403291GlobalBlockingCVE-2025-62656N/AYesYesYes
T405357Page FormsCVE-2025-62657N/AN/AYesYes
GHSA-4j5h-mvj3-m48vEmbedVideo (fork)CVE-2025-59839YesYesN/AYes
T406380WatchAnalyticsCVE-2025-62658N/AYesYesYes

Notes

  • There should be one CVE assigned for T397497 that applied to both repos.
  • The WikiLambda security issues from T404392 do not appear to have made it into an actual release, and therefore have no CVEs. But they are still included here for completeness' sake.
  • The CookieConsent security issue does not appear to have made it into an actual release, and therefore has no CVE. But it is still included here for completeness' sake.

Template

Details

Other Assignee
Mstyles
Related Changes in GitLab:
TitleReferenceAuthorSource BranchDest Branch
One additional CVE to add for the recent supplemental releaserepos/security/wikimedia-cve-assignments!11sbassettT397776-one-more-cvemain
Supplemental Release: Q3 2025repos/security/wikimedia-cve-assignments!9mstylesoct-2025-supp-releasemain
Supplemental Release: Q3 2025repos/security/wikimedia-cve-assignments!8mstylesoct-2025-supp-releasemain
Supplemental Release: Q3 2025repos/security/wikimedia-cve-assignments!7mstylesoct-2025-supp-releasemain
Supplemental Release: Q3 2025repos/security/wikimedia-cve-assignments!6mstylesoct-2025-supp-releasemain
Customize query in GitLab

Related Objects

Event Timeline

There are a very large number of changes, so older changes are hidden. Show Older Changes
sbassett updated Other Assignee, added: Mstyles; removed: mmartorana.
sbassett updated the task description. (Show Details)
sbassett removed a subscriber: Jly.

CVE/Backport Assignments

Start VulnEnd VulnAssignee
T397521 LockdownT400545 Wikistories@mmartorana
T401046 BlueSkyT401220 CirrusSearch@Mstyles
T403093 WebAuthnT406380 WatchAnalytics@sbassett

Note: post your email-formatted updates as comments below (see previous email: T389312#10989232)

For Email:

Skin:BlueSky
+ (T401046, CVE-2025-62665) - Multiple Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I64c9e2983ed6629505f72ef9449c09137b3c69ae

Tilesheets
+ (GHSA-hqfr-7cm9-4h87, CVE-2025-54865) - Potential SQL injection
https://github.com/FTB-Gamepedia/Tilesheets/security/advisories/GHSA-hqfr-7cm9-4h87

ImageRating
+ (T402002, CVE-2025-62664) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/q/Ie42bba0d80bace319cf88d71233db1f598ac613b

SecurePoll
+ (T402076, CVE-2025-11937) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SecurePoll/+/1189186

UploadWizard
+ (T402095, CVE-2025-62663) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/q/I37ea7c8825e9de776e207b3919b451ba2b905369

AdvancedSearch
+ (T402146, CVE-2025-62662) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/q/I91bba2b570643ef74e6c210e7250e05cd2aa388e

Cargo
+ (T402147, CVE-2025-62671) - Stored XSS through wikitext
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1179707

FlexDiagrams
+ (T402149, CVE-2025-62661) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/FlexDiagrams/+/1179692

Thanks
+ (T397497, CVE-2025-62661) - Incorrect permission checking
https://gerrit.wikimedia.org/r/q/Idbc1b5a288ffaa7074eedcbac066358a8ec649dc

GrowthExperiments
+ (T397497, CVE-2025-61654) - Incorrect permission checking
https://gerrit.wikimedia.org/r/q/Ia584966bb7d4d707eef50529293aa3d468470f18

GrowthExperiments
+ (T402698, CVE-2025-62667) - Stored XSS through article extracts
https://gerrit.wikimedia.org/r/q/Iafd0acccf9a5c20d9e955d7bc3de1304968401ec

CirrusSearch
+ (T401220, CVE-2025-62666) - DoS vector through the cirrusbuilddoc query API
https://gerrit.wikimedia.org/r/q/I3e8d819868c0491b18368af8e543180e747023c2

sbassett updated the task description. (Show Details)

For email:

WebAuthn
+ (T403093, CVE-2025-62652) - Stored XSS in WebAuthn key name
https://gerrit.wikimedia.org/r/q/I871ad11a68aad2a6389fdd918de5fcf0921f5a7c

PollNY
+ (T403923, CVE-2025-62653) - Stored XSS through system messages in PollNY
https://gerrit.wikimedia.org/r/q/If235d6e6c1d37de6748ef4774cdb3438f52ac532

QuizGame
+ (T403924, CVE-2025-62654) - Stored XSS through system messages in QuizGame
https://gerrit.wikimedia.org/r/q/Iafb81db227107cd8be204f1b6f4eccd06fbec8ce

3DAlloy
+ (GHSA-f2rp-232x-mqrh, CVE-2025-59332) - Stored XSS through attributes provided to the 3d parser tag/function
https://github.com/dolfinus/3DAlloy/security/advisories/GHSA-f2rp-232x-mqrh

Cargo
+ (T404016, CVE-2025-62655) - SQL injection in Cargo via Special:CargoExport
https://gerrit.wikimedia.org/r/q/I9039a39aa92de193a2f2e9816856adc8c757cf85
https://gerrit.wikimedia.org/r/q/I649ec974c33ad7c4e2338e2f5d8c497153dd6d25

WikiLambda
+ (T404392) - Arbitrary HTML injection through error display on Wikifunctions
https://gerrit.wikimedia.org/r/q/T404392

CookieConsent
+ ( T404475) - CookieConsent should use reserved data attributes to avoid potential XSS vectors
https://gerrit.wikimedia.org/r/q/Ib6a53470f9f00fc180cac9fceddd0a3c43887825

GlobalBlocking
+ (T403291, CVE-2025-62656) - GlobalBlocking Special:GlobalBlockList vulnerable to message key stored XSS
https://gerrit.wikimedia.org/r/q/I684c8ec425c7baa722a694ef23d5b6e2a4c3d57b

PageForms
+ (T405357, CVE-2025-62657) - Stored XSS through system messages in PageForms
https://gerrit.wikimedia.org/r/q/Ic88edd43f356935767730a97ccaf841758c854f1

EmbedVideo (fork)
+ (GHSA-4j5h-mvj3-m48v, CVE-2025-59839) - Stored XSS through wikitext caused by usage of non-reserved data attributes
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-4j5h-mvj3-m48v

WatchAnalytics
+ (T406380, CVE-2025-62658) - SQL injection in WatchAnalytics through Special:ClearPendingReviews
https://gerrit.wikimedia.org/r/q/I6c0018713e0fe0a2ec3610508ea3581e2c8035e4

Email copy for the top part of the CVEs:

Lockdown
+(T397521, CVE-2025-12004) - Compare API module breaks Lockdown Extension
https://gerrit.wikimedia.org/r/q/Id275382743957004fa7fc56318fc104d8e2d267b

DiscordNotifications
+(GHSA-gvfx-p3h5-qf65, CVE-2025-53371) - DOS, SSRF and possible RCE through requests to user-controlled URLs
https://github.com/miraheze/DiscordNotifications/commit/1f20d850cbcce5b15951c7c6127b87b927a5415e
https://github.com/miraheze/DiscordNotifications/security/advisories/GHSA-gvfx-p3h5-qf65

DynamicPageList3
+(GHSA-7pgw-q3qp-6pgq, CVE-2025-53625) - Exposure of hidden/suppressed usernames
https://github.com/Universal-Omega/DynamicPageList3/security/advisories/GHSA-7pgw-q3qp-6pgq

LastModified
+(CVE-2025-62693,T399583) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/Ia406630dbac5ef9a9aed3f402f0ba6e434a6bcf2

MultiBoilerplate
+(CVE-2025-62700, T399658) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I10e205e3027d4772b2cd9801647fc6c171e4b35b

ExternalGuidance
+(CVE-2025-62698, T399662)- Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I8bfb3c2766982f6633f47ed35720d4d9f51da71d

LanguageSelector
+(CVE-2025-62697, T399724) - Improperly sanitized style parameter in LanguageSelector
https://gerrit.wikimedia.org/r/q/I338288e756de4e58a3f1f02a9c205b37f4927935

Translate
+(CVE-2025-62699, T399627) - Edits performed using the Special:Translate tool do not use the correct IP and User-Agent in the CheckUser tool
https://gerrit.wikimedia.org/r/q/Idac164418362c65d0ad37055fe9e0ad134197da3
https://gerrit.wikimedia.org/r/q/I65c740c8ca5130b40463d687e2f0775951abbf22

Springboard
+(CVE-2025-62696, T400422) - Multiple critical security issues including unauthenticated RCE
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Springboard/+/1174003

WikiLambda
+(CVE-2025-62695, T400500) - Stored XSS through system messages
Not currently supported for release branches, on master branch only
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikiLambda/+/1173952

WikiLove
+(CVE-2025-62694, T400525) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikiLove/+/1191439
https://gerrit.wikimedia.org/r/q/I17fc061112f61b4c37b772410b265df060819416

PageTriage
+(CVE-2025-62704, T400526) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I86c5f17364c7351e7c06ce4cc6e5592467bc8dc3

Wikistories
+(CVE-2025-62701, T400545) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I86c3bb7b7ce2d856cd2a5be787b703c85d7c41fa

AdvancedSearch
+ (T402146, CVE-2025-62662) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/q/I91bba2b570643ef74e6c210e7250e05cd2aa388e

A minor issue, but it affected multiple system messages, not just one

Maybe the master/REL1_43/REL1_44 patches should be listed before the REL1_39 one, since it's highly unlikely anybody is using that branch anyway

DiscordNotifications
+(GHSA-gvfx-p3h5-qf65, CVE-2025-53371) - DOS, SSRF and possible RCE through requests to user-controlled URLs
https://github.com/miraheze/DiscordNotifications/commit/1f20d850cbcce5b15951c7c6127b87b927a5415e

Maybe there should also be a link to the advisory here? For Tilesheets and 3DAlloy for example, only the advisory is linked, not the fix

Springboard
+(CVE-2025-62696, T400422) - Multiple critical security issues
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Springboard/+/1174003

I think it would be good to mention RCE here since the current title of this entry is pretty nondescript (to be fair, the title I gave the task is not great either)

WikiLambda
+(CVE-2025-62695, T400500) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikiLambda/+/1173952

Contrary to the note in the task description, this one does affect release branches (e.g. REL1_43), but it wasn't backported as the extension is mainly intended to be used by WMF (T400500#11042550), so either it should still be backported or the email should mention that WikiLambda is not supported (or at least the release branches aren't)

WikiLove
+(CVE-2025-62694, T400525) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikiLove/+/1191439

That's only the separate fix I created for REL1_39, the other ones are here: https://gerrit.wikimedia.org/r/q/I17fc061112f61b4c37b772410b265df060819416

Thanks @SomeRandomDeveloper I think addressed all of your comments. @sbassett will have to address the one for his.

Draft Email For Release - Please comment with any questions/concerns - otherwise this will be sent to the relevant mailing lists on 10/22/2025
Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.14/1.43.4/1.44.1)

Greetings-

With the security/maintenance release of MediaWiki 1.39.14/1.43.4/1.44.1, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]:

Lockdown
+ (T397521, CVE-2025-12004) - Compare API module breaks Lockdown Extension
(Note: this issue was resolved by a MediaWiki core patch)
https://gerrit.wikimedia.org/r/q/Id275382743957004fa7fc56318fc104d8e2d267b

DiscordNotifications
+ (GHSA-gvfx-p3h5-qf65, CVE-2025-53371) - DOS, SSRF and possible RCE through requests to user-controlled URLs
https://github.com/miraheze/DiscordNotifications/security/advisories/GHSA-gvfx-p3h5-qf65
https://github.com/miraheze/DiscordNotifications/commit/1f20d850cbcce5b15951c7c6127b87b927a5415e

DynamicPageList3
+ (GHSA-7pgw-q3qp-6pgq, CVE-2025-53625) - Exposure of hidden/suppressed usernames
https://github.com/Universal-Omega/DynamicPageList3/security/advisories/GHSA-7pgw-q3qp-6pgq

LastModified
+ (T399583, CVE-2025-62693) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/Ia406630dbac5ef9a9aed3f402f0ba6e434a6bcf2

MultiBoilerplate
+ (T399658, CVE-2025-62700) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I10e205e3027d4772b2cd9801647fc6c171e4b35b

ExternalGuidance
+ (T399662, CVE-2025-62698)- Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I8bfb3c2766982f6633f47ed35720d4d9f51da71d

LanguageSelector
+(T399724, CVE-2025-62697) - Improperly sanitized style parameter in LanguageSelector
https://gerrit.wikimedia.org/r/q/I338288e756de4e58a3f1f02a9c205b37f4927935

Translate
+ (T399627, CVE-2025-62699) - Edits performed using the Special:Translate tool do not use the correct IP and User-Agent in the CheckUser tool
https://gerrit.wikimedia.org/r/q/Idac164418362c65d0ad37055fe9e0ad134197da3
https://gerrit.wikimedia.org/r/q/I65c740c8ca5130b40463d687e2f0775951abbf22

Springboard
+ (T400422, CVE-2025-62696) - Multiple critical security issues including unauthenticated RCE
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Springboard/+/1174003

WikiLambda
+ (T400500, CVE-2025-62695) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/Id6e96d54b4dd73af205c69ba8774c0fd51632c87

WikiLove
+ (T400525, CVE-2025-62694) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I17fc061112f61b4c37b772410b265df060819416

PageTriage
+ (CVE-2025-62704, T400526) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I86c5f17364c7351e7c06ce4cc6e5592467bc8dc3

Wikistories
+ (CVE-2025-62701, T400545) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I86c3bb7b7ce2d856cd2a5be787b703c85d7c41fa

Skin:BlueSky
+ (T401046, CVE-2025-62665) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I64c9e2983ed6629505f72ef9449c09137b3c69ae

Tilesheets
+ (GHSA-hqfr-7cm9-4h87, CVE-2025-54865) - Potential SQL injection
https://github.com/FTB-Gamepedia/Tilesheets/security/advisories/GHSA-hqfr-7cm9-4h87

ImageRating
+ (T402002, CVE-2025-62664) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/q/Ie42bba0d80bace319cf88d71233db1f598ac613b

SecurePoll
+ (T402076, CVE-2025-11937) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SecurePoll/+/1189186

UploadWizard
+ (T402095, CVE-2025-62663) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/q/I37ea7c8825e9de776e207b3919b451ba2b905369

AdvancedSearch
+ (T402146, CVE-2025-62662) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/q/I91bba2b570643ef74e6c210e7250e05cd2aa388e

Cargo
+ (T402147, CVE-2025-62671) - Stored XSS through wikitext
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1179707

FlexDiagrams
+ (T402149, CVE-2025-62670) - Stored XSS through a system message
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/FlexDiagrams/+/1179692

Thanks
+ (T397497, CVE-2025-61654) - Incorrect permission checking
https://gerrit.wikimedia.org/r/q/Idbc1b5a288ffaa7074eedcbac066358a8ec649dc

GrowthExperiments
+ (T397497, CVE-2025-61654) - Incorrect permission checking
https://gerrit.wikimedia.org/r/q/Ia584966bb7d4d707eef50529293aa3d468470f18

GrowthExperiments
+ (T402698, CVE-2025-62667) - Stored XSS through article extracts
https://gerrit.wikimedia.org/r/q/Iafd0acccf9a5c20d9e955d7bc3de1304968401ec

CirrusSearch
+ (T401220, CVE-2025-62666) - DoS vector through the cirrusbuilddoc query API
https://gerrit.wikimedia.org/r/q/I3e8d819868c0491b18368af8e543180e747023c2

WebAuthn
+ (T403093, CVE-2025-62652) - Stored XSS in WebAuthn key name
https://gerrit.wikimedia.org/r/q/I871ad11a68aad2a6389fdd918de5fcf0921f5a7c

PollNY
+ (T403923, CVE-2025-62653) - Stored XSS through system messages in PollNY
https://gerrit.wikimedia.org/r/q/If235d6e6c1d37de6748ef4774cdb3438f52ac532

QuizGame
+ (T403924, CVE-2025-62654) - Stored XSS through system messages in QuizGame
https://gerrit.wikimedia.org/r/q/Iafb81db227107cd8be204f1b6f4eccd06fbec8ce

3DAlloy
+ (GHSA-f2rp-232x-mqrh, CVE-2025-59332) - Stored XSS through attributes provided to the 3d parser tag/function
https://github.com/dolfinus/3DAlloy/security/advisories/GHSA-f2rp-232x-mqrh

Cargo
+ (T404016, CVE-2025-62655) - SQL injection in Cargo via Special:CargoExport
https://gerrit.wikimedia.org/r/q/I649ec974c33ad7c4e2338e2f5d8c497153dd6d25
https://gerrit.wikimedia.org/r/q/I9039a39aa92de193a2f2e9816856adc8c757cf85

WikiLambda
+ (T404392) - Arbitrary HTML injection through error display on Wikifunctions
https://gerrit.wikimedia.org/r/q/T404392

CookieConsent
+ (T404475, CVE-2025-62659) - CookieConsent should use reserved data attributes to avoid potential XSS vectors
https://gerrit.wikimedia.org/r/q/Ib6a53470f9f00fc180cac9fceddd0a3c43887825

GlobalBlocking
+ (T403291, CVE-2025-62656) - GlobalBlocking Special:GlobalBlockList vulnerable to message key stored XSS
https://gerrit.wikimedia.org/r/q/I684c8ec425c7baa722a694ef23d5b6e2a4c3d57b

PageForms
+ (T405357, CVE-2025-62657) - Stored XSS through system messages in PageForms
https://gerrit.wikimedia.org/r/q/Ic88edd43f356935767730a97ccaf841758c854f1

EmbedVideo (fork)
+ (GHSA-4j5h-mvj3-m48v, CVE-2025-59839) - Stored XSS through wikitext caused by usage of non-reserved data attributes
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-4j5h-mvj3-m48v

WatchAnalytics
+ (T406380, CVE-2025-62658) - SQL injection in WatchAnalytics through Special:ClearPendingReviews
https://gerrit.wikimedia.org/r/q/I6c0018713e0fe0a2ec3610508ea3581e2c8035e4

The Wikimedia Security Team recommends updating these extensions and/or skins to the current master branch or relevant, supported release branch [2] as soon as possible. Some of the referenced Phabricator tasks above _may_ still be private. Unfortunately, when security issues are reported, sometimes sensitive information is exposed and since Phabricator is historical, we cannot make these tasks public without exposing this sensitive information. If you have any additional questions or concerns regarding this update, please feel free to contact security@wikimedia.org or file a security task within Phabricator [3].

[1] https://phabricator.wikimedia.org/T397776
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs

With the security/maintenance release of MediaWiki 1.39.14/1.43.4/1.44.1, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]:

Due to T406322 we're currently at 1.39.15 / 1.43.5 / 1.44.2 (unless this is supposed to belong to the initial security release)

The CookieConsent security issue does not appear to have made it into an actual release, and therefore has no CVE. But it is still included here for completeness' sake.

Per https://www.mediawiki.org/wiki/Extension:CookieConsent the extension uses the master branch, so I think this can be considered a release

Per https://www.mediawiki.org/wiki/Extension:CookieConsent the extension uses the master branch, so I think this can be considered a release

It looks like it supports tagged releases. And that 2.0.0 should incorporate the security issue fix from T404475. I'm happy to create a CVE for that tagged release, but in general, I think we want to avoid listing master/main as a release going forward, and encourage various maintainers to either use MediaWiki's release branch framework or maintain their own tagged releases, as opposed to just using master/main.

Due to T406322 we're currently at 1.39.15 / 1.43.5 / 1.44.2 (unless this is supposed to belong to the initial security release)

It should match the core release: T389302: Release MediaWiki 1.39.13/1.42.7/1.43.2.

sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett changed the edit policy from "Subscribers" to "All Users".