mediawiki
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting mediawiki.
- CVE-2024-23176An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.5.4
- CVE-2023-37253An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.3.1
- CVE-2023-37252An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.3.1
- CVE-2026-14363Cargo Extension: SQLi in Special:Drilldown9.8
- CVE-2026-14358Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title6.1
- CVE-2026-58517Blocked users can create and edit WikiLambda objects4.3
- CVE-2026-58521SQLi in Cargo extension via year range filter9.8
- CVE-2026-58520UrlShortener defaults to ineffective validation open to third-party redirects6.1
- CVE-2026-58025Remote Code Execution via Unsafe Deserialization in LogItem Import9.8
- CVE-2026-58029Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata6.5
- CVE-2026-58028Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets5.4
- CVE-2026-58026$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces5.7
- CVE-2026-8857Full RCE using EasyTimeline Extension8.8
- CVE-2026-58038Stored XSS through javascript URLs in SVGs generated by EasyTimeline6.1
- CVE-2026-58027QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI6.5