In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.
{ "binaries": [ { "binary_version": "1:1.27.4-3", "binary_name": "mediawiki" }, { "binary_version": "1:1.27.4-3", "binary_name": "mediawiki-classes" } ] }
{ "binaries": [ { "binary_version": "1:1.31.7-1", "binary_name": "mediawiki" }, { "binary_version": "1:1.31.7-1", "binary_name": "mediawiki-classes" } ] }
{ "binaries": [ { "binary_version": "1:1.35.6-1", "binary_name": "mediawiki" }, { "binary_version": "1:1.35.6-1", "binary_name": "mediawiki-classes" } ] }
{ "binaries": [ { "binary_version": "1:1.39.7-1", "binary_name": "mediawiki" }, { "binary_version": "1:1.39.7-1", "binary_name": "mediawiki-classes" } ] }
{ "binaries": [ { "binary_version": "1:1.43.1+dfsg-1", "binary_name": "mediawiki" }, { "binary_version": "1:1.43.1+dfsg-1", "binary_name": "mediawiki-classes" } ] }