(:A cross-site scripting vulnerability has been reported in the Parsoid service of MediaWiki.:A remote attacker could exploit it by enticing their victim into following a specially formed link in order to execute arbitrary JavaScript or HTML code.::This vulnerability is due to an improper handling of user-supplied input.::A proof of concept is available.)