<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PageForms - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pageforms/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 19:34:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pageforms/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in PageForms Extension</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-103445/</link><pubDate>Wed, 30 Sep 2026 19:34:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-103445/</guid><description>A stored XSS vulnerability in the PageForms extension allows attackers with page-edit permissions to inject malicious javascript: URIs via the redirect parameter.</description><content:encoded><![CDATA[<p>CVE-2026-103445 is a stored Cross-Site Scripting (XSS) vulnerability affecting the PageForms extension. The vulnerability exists because the extension fails to properly validate the URI scheme when processing the 'redirect' parameter used in the 'href' attribute of generated links. An attacker with ordinary page-edit permissions can craft a malicious wikitext entry containing a 'javascript:' URI. When a legitimate user or administrator interacts with the resulting link on the wiki page, the arbitrary JavaScript executes in the context of the victim's browser session. This vulnerability was disclosed and verified with a public proof-of-concept on September 30, 2026. Given the low CVSS severity (2.1), this issue primarily poses a risk in environments where users with edit permissions are not fully trusted or where social engineering campaigns could leverage the link to hijack administrative sessions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the execution of arbitrary JavaScript in the context of a victim's browser session. While the severity is low, potential impacts include session hijacking, unauthorized actions performed on behalf of the victim, or the theft of sensitive session cookies if anti-XSS headers are not strictly enforced. The vulnerability affects users of the PageForms extension across any platform running the affected version.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching the PageForms extension by applying the fix available in the Wikimedia Gerrit repository. Given the nature of XSS, detection engineering teams should review web access logs and Content Security Policy (CSP) configurations to ensure unauthorized scripts are blocked from execution.</p>
<ul>
<li>Apply the security patch for CVE-2026-103445 provided at the referenced Gerrit URL.</li>
<li>Audit wiki page content for suspicious 'href' attributes containing 'javascript:' URI schemes.</li>
<li>Implement or strengthen Content Security Policy (CSP) headers to restrict inline script execution and block unauthorized domains.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>pageforms</category></item></channel></rss>