Mediawiki
This hub aggregates every CVE we track for Mediawiki, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
398
CVEs tracked
20
Critical
75
High
0
In CISA KEV
Severity distribution
MEDIUM289HIGH75CRITICAL20LOW14
Monthly trend
10
0
0
1
0
0
0
0
0
6
0
0
1
0
0
0
0
0
0
13
0
0
7
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Mediawiki.
- CVE-2026-34095action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request6.1
- CVE-2026-34094Customized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefix3.8
- CVE-2026-34093Special:UserRights allows viewing user rights from private wiki5.3
- CVE-2026-34092Block UI elements in 'tools'-sidebar shows presence of an autoblocked IP7.5
- CVE-2026-34091User localization leaked by AbuseFilter + EventStream7.5
- CVE-2026-34088RecentChanges entries expose suppressed content via generated log page html7.5
- CVE-2026-34087Users API leaks whether privileged users have their user groups disabled for lack of 2FA7.5
- CVE-2025-67484Action API xslt option allows JavaScript execution by administrators who are not interface administrators9.8
- CVE-2025-67480list=allrevisions can be used to bypass Extension:Lockdown6.5
- CVE-2025-67476Importing leaks IP address of importer via EventStreams4.3
- CVE-2025-61637Stored XSS through system messages in MW Core4.8
- CVE-2025-61638Sanitizer::validateAttributes data-XSS4.8
- CVE-2025-61639Suppressed blocked IP is visible in Special:BlockList, RC, and other places4.8
- CVE-2025-61640Stored XSS through system messages in Special:RecentChangesLinked (MW Core)4.8
- CVE-2025-6590Complete content leak of private wikis due to PasswordReset Wikitext injection in error message5.4
Product normalization is registry-driven with AI assist and human review. How it works