高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Wikimedia Foundation | VisualEditor | * ~ 1.39.14, 1.43.4, 1.44.1 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2025-67477 | Stored XSS through a system message in Special:ApiSandbox | |
| CVE-2025-67483 | Theoretical i18n XSS in mediawiki.page.preview.js when a page has multiple protection leve | |
| CVE-2025-67481 | mw.message(…).parse() doesn't output safe HTML, but it's being used as if it does | |
| CVE-2025-67484 | Action API xslt option allows JavaScript execution by administrators who are not interface | |
| CVE-2025-67482 | Lua segfault in unpack() | |
| CVE-2025-61658 | Special:GlobalContributions shows edits on wikis the viewer doesn't have access to | |
| CVE-2025-61656 | XSS when pasting into VE | |
| CVE-2025-61651 | i18n XSS through Special:CheckUser CheckUser helper | |
| CVE-2025-61654 | UserInfoCard: Do permission checking when getting counts of global and local edits, new ar | |
| CVE-2025-61657 | Wikimedia Vector 安全漏洞 | |
| CVE-2025-61653 | Extension:TextExtracts does not check for authorizeRead when returning extracts | |
| CVE-2025-61652 | Action API discussiontoolspageinfo does not check for authorizeRead for the page | |
| CVE-2025-67476 | Importing leaks IP address of importer via EventStreams | |
| CVE-2025-61647 | UserInfoCard: Don't allow access to information about users who are suppressed if you don' | |
| CVE-2025-67475 | Stored XSS through edit summaries in MW Core | |
| CVE-2025-67480 | list=allrevisions can be used to bypass Extension:Lockdown | |
| CVE-2025-67479 | Magic word replacement in legacy parser allows using reserved data attributes through wiki | |
| CVE-2025-67478 | Wrong E-Mail address composition for usernames with a comma and Umlauts in it like "Döe, J | |
| CVE-2025-61649 | UserInfoCard: Check that performing user has permission to view log entries for number of | |
| CVE-2025-61648 | Stored XSS through system messages in CheckUser |
Showing 20 of 26 CVEs. View all on vendor page →
まだコメントはありません