An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23178.json"