Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/bombobombone/cve-2026-103445
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb Security
GitHubbombobombone/cve-2026-103445

CVE-2026-103445

Report summary and local proof-of-concept for CVE-2026-103445, a stored XSS in MediaWiki PageForms #autoedit via javascript: redirect URLs.

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-103445: Stored XSS through PageForms #autoedit

Reporter: Marco Paciaroni (BomboBombone).

PageForms used the redirect parameter as a generated link's href without rejecting executable schemes. An editor with ordinary page-edit permission could save a javascript: URL that ran when a visitor clicked the link.

Proof of concept

Run the script to print the PoC wikitext. Save it on a disposable, editable page in a local wiki with PageForms enabled, then click the generated Trigger link. The marker adds a data attribute to the page body.

python poc.py

Use only a local test wiki.

References

  • CVE record
  • Public Phabricator report
  • PageForms fix on Gerrit
  • Blog write-up
Download Tool