Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-100380 — PoC and patch verification notes for CVE-2026-100380, a reflected XSS in Wikibase language-validation error pages, with a script that detects unescaped HTML output. | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-100380
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPapers & Research
GitHubbombobombone/cve-2026-100380

CVE-2026-100380

PoC and patch verification notes for CVE-2026-100380, a reflected XSS in Wikibase language-validation error pages, with a script that detects unescaped HTML output.

View Repository
4 days agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-100380: Reflected XSS in language-validation errors

Reporter: Marco Paciaroni (BomboBombone).

Wikibase included unescaped language-validation error text in the SetLabel page. Rejected input could be returned as executable HTML before the request reached the label-saving operation.

Affected versions

The CVE record identifies affected Wikibase release branches before the fixes in 1.46.1, 1.45.5, and 1.43.10. Use the fixed extension code for the corresponding MediaWiki release branch.

Impact and conditions

The archived validation records an unauthenticated request and browser execution in the wiki origin. No label save was reached. Rejecting a write does not protect an error page that renders untrusted input as HTML.

Recorded validation

The archived case evidence records a successful local HTTP response and browser execution of a harmless marker. It separately records that no label save occurred. This public summary is based on those validation records and the associated research notes.

Fix

The upstream change HTML-escapes error messages in term-editing and related special pages before rendering them.

Proof of concept

python poc.py https://wiki.example --entity Q1

The script posts an invalid language value containing a harmless marker and checks whether the response returns it as a raw script element. The affected path rejects the request before saving a label.

References

  • CVE record
  • Upstream fix
  • Upstream tracking task
  • Blog write-up
Download Tool