The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | 1.35 | 1.35.x |