Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2914 articles · 109747 vulns · 38/41 feeds (7d)
← Back to list
7.5
CVE-2026-39837PATCHED
wikimedia foundation · mediawiki - cargo extension

Stored XSS through the dynamic table format in Cargo

Description

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

Affected Products

VendorProductVersions
wikimedia foundationmediawiki - cargo extension0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcemediawikicert_advisory90%

References

  • https://phabricator.wikimedia.org/T416402
  • https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237979

Related News (2 articles)

Tier B
BSI Advisories4h ago
[NEU] [hoch] MediaWiki Erweiterungen: Mehrere Schwachstellen ermöglichen Cross-Site Scripting
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2026-39837 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting
→ No new info (linked only)
CVSS 3.17.5 HIGH
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.8.7
CWECWE-80
PublishedApr 7, 2026
Last enriched2d agov2
Tags
CVE-2026-39837
Trending Score46
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-39840EXP
CSS injection in multiple Cargo display formats
Trending: 65
NONECVE-2026-39934EXP
Growth Experiments ReassignMenteesJob runs as an infinite loop
Trending: 60
NONECVE-2026-5762EXP
ReportIncident DiscussionTools integration causes slow requests
Trending: 58
HIGHCVE-2026-39839
Stored XSS through URLs in Cargo's map format
Trending: 46
HIGHCVE-2026-39841
Stored XSS through list fields on Cargo's page values and Special:CargoTables
Trending: 46

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Patch Available
Apr 7, 2026
Updated: severity, cvssEstimate, tags
Apr 7, 2026

Version History

v2
Last enriched 2d ago
v2Tier C2d ago

Updated severity to HIGH, added CVSS estimate of 7.5, and corrected exploit availability status.

severitycvssEstimatetags
via VulDB
v12d ago

Initial creation