Where
-Infinity
0

MediaWiki ManageWikiManageWiki Vulnerable to Self-XSS in review dialog via unsanitized field reflection

Risk 25
Severity
5.4
EPSS
0.03%
First published (updated )

MediaWiki ManageWikiManageWiki vulnerable to permission bypass when disabling extensions requiring certain permissions in Special:ManageWiki/extensions

Risk 22
Severity
4.6
EPSS
0.03%
First published (updated )

MediaWiki ManageWikiManageWiki has SQL injection vulnerability in NamespaceMigrationJob

Risk 52
Severity
8
EPSS
0.03%
First published (updated )

Wikimedia Foundation Mediawiki - Version Compare ExtensionXSSes and potential RCE in Special:VersionCompare

Risk 35
Severity
6.9
EPSS
0.06%
First published (updated )

Wikimedia Foundation Mediawiki - Mobile Frontend ExtensionCross-origin data leak in mobilefrontend via lazy load images

Risk 35
Severity
6.9
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wikimedia Foundation Mediawiki Core - Feed UtilsHTML injection in feed output from i18n message

Risk 35
Severity
6.9
EPSS
0.06%
First published (updated )

Wikimedia Foundation Mediawiki - HTML TagsSystem message XSS in HTMLTags

Risk 25
Severity
5.4
EPSS
0.10%
First published (updated )

Wikimedia Foundation Mediawiki - Tabs ExtensionIP and user agent leaks in Extension:Tabs

Risk 35
Severity
6.9
EPSS
0.10%
First published (updated )

Wikimedia Foundation MediaWikiPotential javascript injection attack enabled by Unicode normalization in Action API

Risk 11
Severity
2.1
EPSS
0.09%
First published (updated )

Wikimedia Foundation MediaWikiLogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions

Risk 11
Severity
2.1
EPSS
0.08%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wikimedia Foundation MediaWikiCascading protection is not preventing file reversions

Risk 2
Severity
1
EPSS
0.05%
First published (updated )

Wikimedia Foundation MediaWiki"reupload-own" restriction can be bypassed by reverting file

Risk 2
Severity
1
EPSS
0.05%
First published (updated )

Wikimedia Foundation MediaWikii18n XSS vulnerability in HTMLMultiSelectField when sections are used

Risk 2
Severity
1
EPSS
0.09%
First published (updated )

Wikimedia Foundation MediaWiki - GlobalBlocking ExtensionAPI list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameter

Risk 14
Severity
3.5
EPSS
0.04%
First published (updated )

Wikimedia Foundation Mediawiki - ArticleFeedbackv5XSSes in Extension:ArticleFeedbackv5

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wikimedia Foundation MediaWiki 1.41Reached end of life

EOL
Dec 31, 2024
First published (updated )

Wikimedia Foundation MediaWiki 1.41Reached end of life

EOL
Dec 31, 2024
First published (updated )

Wikimedia Wikimedia-extensions-cssPath traversal when loading stylesheets

Risk 43
Severity
7.5
First published (updated )

Wikimedia Wikimedia-extensions-cssCSS sanitizer used incorrectly, and is easily bypassed

Risk 53
Severity
8.2
First published (updated )

Wikimedia Foundation Mediawiki - PageTriageUser can review/unreview articles while blocked

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MediaWiki MediaWikiCSRF

Risk 22
Severity
4.3
First published (updated )

MediaWiki MediaWikiXSS

Risk 29
Severity
4.8
First published (updated )

MediaWiki MediaWikiXSS

Risk 38
Severity
6.1
First published (updated )

MediaWiki MediaWikiXSS

Risk 29
Severity
4.8
First published (updated )

MediaWiki MediaWikiXSS

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MediaWiki MediaWikiCSRF

Risk 37
Severity
6.5
First published (updated )

MediaWiki MediaWikiAn issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose …

Risk 22
Severity
4.3
First published (updated )

MediaWiki MediaWikiXSS

Risk 29
Severity
4.8
First published (updated )

MediaWiki MediaWikiCSRF

Risk 61
Severity
9.8
EPSS
0.04%
First published (updated )

MediaWiki MediaWikiXSS

Risk 30
Severity
7.4
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203