
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61656 is a security vulnerability in MediaWiki related to sanitization of attributes unwrapped from data-ve-attributes. The vulnerability was first published on October 7, 2025, and last updated on October 8, 2025. It affects multiple versions of MediaWiki, including versions in Ubuntu and Debian distributions (Ubuntu Security, Debian Tracker).
The vulnerability involves improper sanitization of attributes that are unwrapped from data-ve-attributes in MediaWiki's Visual Editor component. The issue affects multiple MediaWiki releases including versions 1.35.13, 1.39.13, and 1.43.3 (Debian Tracker).
The vulnerability is currently assessed with a Medium priority rating according to Ubuntu's security assessment (Ubuntu Security).
Currently, the vulnerability remains unpatched across multiple versions of MediaWiki. The issue is marked as 'needs evaluation' for Ubuntu releases 25.10, 25.04, 24.04 LTS, 22.04 LTS, 20.04 LTS, and 18.04 LTS (Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."