# CVE-2025-21612

## Summary

- **CVE ID:** CVE-2025-21612
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L)
- **CWE:** CWE-79, CWE-80
- **Published:** Jan 6, 2025
- **Last Modified:** Mar 12, 2026

## Description

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.

## Affected Products

- StarCitizenTools — mediawiki-extensions-TabberNeue (>= 1.9.1, < 2.7.2)
- StarCitizenTools — mediawiki-extensions-TabberNeue (>= d8c3db4e5935476e496d979fb01f775d3d3282e6, < f229cab099c69006e25d4bad3579954e481dc566)

## References

- [CNA](https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/security/advisories/GHSA-4x6x-8rm8-c37j)
- [CNA](https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/commit/d8c3db4e5935476e496d979fb01f775d3d3282e6)
- [CNA](https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/commit/f229cab099c69006e25d4bad3579954e481dc566)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 41.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._