Description
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
Remediation
References
Related Vulnerabilities
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5096)
WordPress Plugin cformsII Multiple Cross-Site Scripting Vulnerabilities (14.13.2)
WordPress Plugin Email Before Download SQL Injection (6.7)
WordPress Plugin WooCommerce Information Disclosure (4.5.2)
Moodle Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-1042)