CVE-2025-53368 | Citizen is vulnerable to stored XSS attack in the legacy search bar
Exp
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-site scripting (XSS) payloads into the DOM for other users who are searching for specific pages. This issue has been patched in version 3.4.0.
Conclusion & alert: CVE-2025-53368 is rated Exploit Available (56.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.28%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2025-53368
Exploit prediction scoring system (EPSS) score for CVE-2025-53368
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
GHSA-rq6g-6g94-jfr4 · Severity: high · Ecosystem: composer — starcitizentools/citizen-skin is vulnerable to Stored XSS attack in the legacy search bar through page descriptions
Affected software / configurations for CVE-2025-53368