Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MediaWiki — Vulnerabilities & Security Advisories 75

All 75 CVE vulnerabilities found in MediaWiki, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) associated with the open-source wiki software product MediaWiki, developed by the Wikimedia Foundation and various community contributors. It serves as a centralized resource for tracking security weaknesses and their manifestations within this specific software ecosystem, providing a structured view of historical and current threats. The content collected here covers a broad range of vulnerability types, including cross-site scripting (XSS), information disclosure, remote code execution, and authentication bypass flaws. The time range spanned by these records extends from the early days of the software’s widespread adoption up to recent years, reflecting the evolving security landscape and remediation efforts over decades. Readers can use this aggregation to track vendor advisories and understand how specific weakness classes have impacted MediaWiki installations. It allows security professionals to examine the product’s vulnerability history, identifying patterns in exploitability and fix timelines. By reviewing these aggregated entries, users can gain insight into the overall security posture of MediaWiki, assess potential risks for their deployments, and compare the severity and frequency of different attack vectors. This resource supports informed decision-making for administrators and developers seeking to harden their wiki instances against known exploits. It emphasizes transparency by linking reported issues to their respective resolution statuses, facilitating a deeper understanding of the remediation process. Ultimately, the goal is to provide a clear, factual overview of security challenges without promoting any particular viewpoint or solution.

Vendor: mediawiki

CVE IDTitleCVSSSeverityPublished
CVE-2026-58025 Remote Code Execution via Unsafe Deserialization in LogItem Import CWE-502--2026-07-01
CVE-2026-58029 Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata --2026-07-01
CVE-2026-58028 Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets CWE-79--2026-07-01
CVE-2026-58026 $wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces CWE-200--2026-07-01
CVE-2026-58032 mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html CWE-79--2026-07-01
CVE-2026-58033 "Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted CWE-200--2026-07-01
CVE-2026-58037 Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input CWE-79--2026-07-01
CVE-2026-58036 Users API leaks whether privileged users have their user groups disabled for lack of 2FA CWE-200--2026-07-01
CVE-2026-58024 API identification of users on private wikis CWE-200--2026-07-01
CVE-2026-58031 Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected CWE-79--2026-07-01
CVE-2026-58035 Stored XSS through a system message in the codex version of Special:Block CWE-79--2026-07-01
CVE-2026-34095 action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request --2026-05-11
CVE-2026-34094 Customized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefix --2026-05-11
CVE-2026-34093 Special:UserRights allows viewing user rights from private wiki CWE-200--2026-05-11
CVE-2026-34092 Block UI elements in 'tools'-sidebar shows presence of an autoblocked IP CWE-200--2026-05-11
CVE-2026-34091 User localization leaked by AbuseFilter + EventStream CWE-200--2026-05-11
CVE-2026-34088 RecentChanges entries expose suppressed content via generated log page html CWE-200--2026-05-11
CVE-2025-67481 mw.message(…).parse() doesn't output safe HTML, but it's being used as if it does CWE-79 6.1AIMediumAI2026-02-03
CVE-2025-67483 Theoretical i18n XSS in mediawiki.page.preview.js when a page has multiple protection levels CWE-79 6.1AIMediumAI2026-02-03
CVE-2025-67484 Action API xslt option allows JavaScript execution by administrators who are not interface administrators 9.8AICriticalAI2026-02-03
CVE-2025-67480 list=allrevisions can be used to bypass Extension:Lockdown 9.8AICriticalAI2026-02-03
CVE-2025-67475 Stored XSS through edit summaries in MW Core CWE-79 6.1AIMediumAI2026-02-03
CVE-2025-67476 Importing leaks IP address of importer via EventStreams 9.8AICriticalAI2026-02-03
CVE-2025-67477 Stored XSS through a system message in Special:ApiSandbox CWE-79 6.1AIMediumAI2026-02-03
CVE-2025-67479 Magic word replacement in legacy parser allows using reserved data attributes through wikitext 9.1AICriticalAI2026-02-03
CVE-2025-11261 Stored i18n XSS exposed by security patch for T402077 CWE-79 6.1AIMediumAI2026-02-03
CVE-2025-61645 CodexTablePager has i18n XSS CWE-79 6.1AIMediumAI2026-02-03
CVE-2025-61646 Watchlist group mode reveals authors of edits with hidden authorship 8.2AIHighAI2026-02-03
CVE-2025-61644 i18n XSS through Special:Watchlist CWE-79 6.1AIMediumAI2026-02-02
CVE-2025-61637 Stored XSS through system messages in MW Core CWE-79 6.1AIMediumAI2026-02-02

All 75 known CVE vulnerabilities affecting MediaWiki with full Chinese analysis, references, and POCs where available.