CVE-2016-6333
Status: ModifiedMedium (6.1)—
Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Base score: 6.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.02%
- Percentile among all scored CVEs: 62
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
- http://www.securityfocus.com/bid/98053
- https://bugzilla.redhat.com/show_bug.cgi?id=1369613
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2016-August/000195.html
- https://phabricator.wikimedia.org/T133147
- http://www.securityfocus.com/bid/98053
- https://bugzilla.redhat.com/show_bug.cgi?id=1369613
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2016-August/000195.html
- https://phabricator.wikimedia.org/T133147
Raw JSON (NVD)
Show
{
"id": "CVE-2016-6333",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-04-20T17:59:00.633",
"references": [
{
"url": "http://www.securityfocus.com/bid/98053",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1369613",
"tags": [
"Issue Tracking"
],
"source": "secalert@redhat.com"
},
{
"url": "https://lists.wikimedia.org/pipermail/mediawiki-announce/2016-August/000195.html",
"tags": [
"Mailing List",
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://phabricator.wikimedia.org/T133147",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/98053",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1369613",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.wikimedia.org/pipermail/mediawiki-announce/2016-August/000195.html",
"tags": [
"Mailing List",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://phabricator.wikimedia.org/T133147",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css."
},
{
"lang": "es",
"value": "Vulnerabilidad XSS en la función de vista previa de subpáginas de usuario CSS en MediaWiki en versiones anteriores a 1.23.15, 1.26.x en versiones anteriores a 1.26.4 y 1.27.x en versiones anteriores a 1.27.1 permite atacantes remotos inyectar secuencias de comandos web o HTML arbitraria a través del cuadro de edición en Special: MyPage / common.css."
}
],
"lastModified": "2026-06-17T00:50:50.727",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F26807BC-B2F2-480D-B5B1-C2D64933A0C8",
"versionEndIncluding": "1.23.14"
},
{
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.26.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B418525-DAC2-461A-B931-BED05CC3AFBF"
},
{
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.26.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C238723-5592-4F0F-869D-91B64DD14FBF"
},
{
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.26.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22685E70-3EE0-484B-8A4C-139C28BDD2B1"
},
{
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.26.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3BD0A725-B06B-456D-8A8B-9DA5468935FA"
},
{
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.26.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7ED98FFC-4397-4F27-AC36-BB7A42A92F89"
},
{
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.27.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F75E06F7-6D23-4BEB-80B4-3DE33193CA95"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}