CVE-2025-61645

CodexTablePager has i18n XSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/pager/CodexTablePager.Php. This issue affects MediaWiki: from * before 1.44.1.


We have discovered 13,431 live websites that are affected by CVE-2025-61645.

Run a Free Instant Scan




Affected Software

Product  MediaWiki
Category Wikis
Vulnerable Domains13,431 live websites (85% of MediaWiki install base)
Vulnerable Versions
  • from 0 through 1.44.1
Vulnerable Versions Count219 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 3, 2026
  • Updated - Feb 3, 2026

Website Distribution by Country

Number of websites using CVE-2025-61645
United States5,737 websites



Germany2,531 websites
France776 websites
Russia635 websites
Netherlands375 websites
GB329 websites
Singapore246 websites
Canada178 websites
Switzerland156 websites

Website Distribution by TLD

Number of websites using CVE-2025-61645
.com4,314 websites
.org2,734 websites
.de1,226 websites
.net1,010 websites
.ru488 websites
.info268 websites
.nl233 websites
.fr222 websites
.eu170 websites
.edu122 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-61645

Top websites that are affected by CVE-2025-61645. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
****************.de Germany***
*******.com United States*,***
*************.org United States*,***
****.*******.org United States*,***
****.*************.org Netherlands*,***
****.******.org United States*,***
****.******.org United States*,***
*******.com Singapore*,***
****.******.com United States*,***
See full domain list

FAQ

CVE-2025-61645 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MediaWiki
A total of 13,431 websites have been identified as vulnerable to CVE-2025-61645, based on global website indexing conducted by WebTechSurvey.
The MediaWiki is affected by the CVE-2025-61645 vulnerability.
MediaWiki versions up to 1.44.1 are vulnerable to CVE-2025-61645.
CVE-2025-61645 is resolved in version 1.44.1 of MediaWiki.