GHSA-p85q-mww9-gwqf · Severity: high · Ecosystem: composer — Citizen Short Description stored XSS vulnerability through wikitext
Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 4.0.1.
Conclusion & alert: CVE-2025-53369 is rated Moderate Risk (55.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-29 | 0.05% | 0.36% | +0.31% |
| 2 | 2025-12-11 | 0.05% | 0.05% | +0.01% |
| 3 | 2025-11-29 | — | 0.05% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.6 | 3.1 | HIGH |
|
3.9 | 4.7 | [email protected] |
GHSA-p85q-mww9-gwqf · Severity: high · Ecosystem: composer — Citizen Short Description stored XSS vulnerability through wikitext
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||