Hi everyone, On Oct 16 2021, we discovered this XSS STORED vulnerability at https://commons.wikimedia.org/ and at that time we immediately reported it to Team WikiMedia. Let’s take a minute to look at this. At that time, we found a subdomain https://commons.wikimedia.org/ , and there was a File upload feature.