the-wikimedia-foundation
Web & CMS Pluginsoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting the-wikimedia-foundation.
- CVE-2026-14363Cargo Extension: SQLi in Special:Drilldown9.8
- CVE-2026-14358Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title6.1
- CVE-2026-58517Blocked users can create and edit WikiLambda objects4.3
- CVE-2026-58521SQLi in Cargo extension via year range filter9.8
- CVE-2026-58520UrlShortener defaults to ineffective validation open to third-party redirects6.1
- CVE-2026-58519Stored XSS through Cargo's map format5.4
- CVE-2026-58518Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager ...6.3
- CVE-2026-22712ApprovedRevs allows bypassing the inline CSS sanitizer4.3
- CVE-2026-22713Stored XSS through edit summaries in GrowthExperiments5.4
- CVE-2026-22710Stored XSS through autocomment system messages in Wikibase5.4
- CVE-2025-32079Saving the right content to MediaWiki:GrowthMentors.json can take down the site6.5
- CVE-2025-32072HTML injection in feed output from i18n message8.3
- CVE-2025-32073System message XSS in HTMLTags5.4
- CVE-2025-32074XSSes in Extension:ConfirmAccount5.4
- CVE-2025-32067i18n XSS vulnerability in message growthexperiments5.4