Last modified: 2012-11-29 12:42:19 UTC
Several places in the code values are passed on without being properly escaped by htmlspecialchars or similar. Use this as a tracking bug for patchsets related to this problem.
repo/includes/actions/EditEntityAction.php https://gerrit.wikimedia.org/r/#/c/25242/
repo/includes/special/SpecialCreateEntity.php https://gerrit.wikimedia.org/r/25244
repo/includes/special/SpecialItemByTitle.php https://gerrit.wikimedia.org/r/25246
repo/includes/ItemView.php https://gerrit.wikimedia.org/r/25249
repo/includes/special/SpecialItemDisambiguation.php https://gerrit.wikimedia.org/r/#/c/25180/
Verified in Wikidata demo time for sprint 17