Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.43"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.44"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.45"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22712.json"