CVE-2026-39839
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki – Cargo Extension allows Stored XSS.This issue affects Mediawiki – Cargo Extension: before 3.8.7.
More information : https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237957
