Description
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Support Plus Responsive Ticket System Cross-Site Scripting (9.1.1)
OpenSSL Key Management Errors Vulnerability (CVE-2016-7055)
Magento Improper Input Validation Vulnerability (CVE-2015-6497)
WordPress Plugin WP Google Maps Multiple Cross-Site Scripting Vulnerabilities (8.1.12)
WordPress 4.5.x Cross-Site Scripting Vulnerability (4.5 - 4.5.1)