Description
In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.
Remediation
References
Related Vulnerabilities
WordPress Plugin JW Player 6 Cross-Site Scripting (2.1.14)
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.22)
WordPress Plugin WP Photo Album Plus Unspecified Vulnerability (7.2.04)
WordPress Plugin Category Specific RSS feed Subscription Cross-Site Request Forgery (2.0)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (3.2.15)