Mediawiki
This hub aggregates every CVE we track for Mediawiki, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
420
CVEs tracked
21
Critical
79
High
0
In CISA KEV
Severity distribution
MEDIUM306HIGH79CRITICAL21LOW14
Monthly trend
0
1
0
0
0
0
0
6
0
0
1
0
0
0
0
0
0
13
0
0
7
0
22
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Mediawiki.
- CVE-2026-14358Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title6.1
- CVE-2026-58517Blocked users can create and edit WikiLambda objects4.3
- CVE-2026-58520UrlShortener defaults to ineffective validation open to third-party redirects6.1
- CVE-2026-58025Remote Code Execution via Unsafe Deserialization in LogItem Import9.8
- CVE-2026-58029Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata6.5
- CVE-2026-58028Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets5.4
- CVE-2026-58026$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces5.7
- CVE-2026-8857Full RCE using EasyTimeline Extension8.8
- CVE-2026-58038Stored XSS through javascript URLs in SVGs generated by EasyTimeline6.1
- CVE-2026-58027QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI6.5
- CVE-2026-58030SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute6.1
- CVE-2026-58032mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html6.1
- CVE-2026-58033"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted6.5
- CVE-2026-58037Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input6.1
- CVE-2026-58036Users API leaks whether privileged users have their user groups disabled for lack of 2FA7.5
Product normalization is registry-driven with AI assist and human review. How it works