
Report summary and local proof-of-concept for CVE-2026-103445, a stored XSS in MediaWiki PageForms #autoedit via javascript: redirect URLs.
#autoeditReporter: Marco Paciaroni (BomboBombone).
PageForms used the redirect parameter as a generated link's href without rejecting executable schemes. An editor with ordinary page-edit permission could save a javascript: URL that ran when a visitor clicked the link.
Run the script to print the PoC wikitext. Save it on a disposable, editable page in a local wiki with PageForms enabled, then click the generated Trigger link. The marker adds a data attribute to the page body.
python poc.py
Use only a local test wiki.