ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-53370
+1 in the same advisory: …53368
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience.

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription extension are inserted as raw HTML by the Citizen skin, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 3.4.0.

NVD description · AI analysis pending
5.4<1% PoC
  • starcitizen.tools citizen
CVE-2025-49578
+4 in the same advisory: …49577 …49576 …49575 …49579
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience.

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • starcitizen.tools citizen
CVE-2024-47536
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience.

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.

NVD description · AI analysis pending
4.8<1% PoC
  • starcitizen.tools citizen
CVE-2024-36123
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience.

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the `editinterface` permission, or sysops). This vulnerability is fixed in 2.16.0.

NVD description · AI analysis pending
5.4<1% PoC
  • starcitizen.tools citizen