Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-100381 — Report and PoC for CVE-2026-100381, a DOM XSS in MediaWiki UploadWizard Flickr collection and set titles, with patch verification notes and a local test harness. | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-100381
Vulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubbombobombone/cve-2026-100381

CVE-2026-100381

Report and PoC for CVE-2026-100381, a DOM XSS in MediaWiki UploadWizard Flickr collection and set titles, with patch verification notes and a local test harness.

View Repository
4 days agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-100381: DOM XSS in Flickr collection and set titles

Reporter: Marco Paciaroni (BomboBombone).

UploadWizard inserted Flickr collection and set titles through an API that interpreted strings as HTML. External title metadata could therefore become executable markup in the wiki page.

Affected versions

The CVE record identifies affected UploadWizard release branches before the fixes in 1.46.1, 1.45.5, and 1.43.10. Use the fixed extension code for the corresponding MediaWiki release branch.

Impact and conditions

Flickr importing had to be enabled, and the victim had to be allowed to use that workflow. The attacker needed control of the external collection metadata. The finding does not establish exposure in deployments where Flickr importing is disabled.

Recorded validation

The original report records browser execution for both collection and set titles in a local instance using a controlled Flickr-compatible service. The validation did not submit an upload.

Fix

The upstream change inserts collection and set titles as text, preserving the surrounding list and link structure without parsing title metadata as HTML.

Proof of concept

python -m pip install websocket-client
python poc.py --wiki http://127.0.0.1:4004 --username TestUser

The local test wiki must have UploadWizard's Flickr integration pointed at the loopback fixture started by the script. The PoC prompts for the password without exposing it in the process list, opens the real workflow in a local headless browser, and checks harmless collection and set markers without submitting an upload.

References

  • CVE record
  • Upstream fix
  • Upstream tracking task
  • Blog write-up
Download Tool