Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MediaWiki — Vulnerabilities & Security Advisories 75

All 75 CVE vulnerabilities found in MediaWiki, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) associated with the open-source wiki software product MediaWiki, developed by the Wikimedia Foundation and various community contributors. It serves as a centralized resource for tracking security weaknesses and their manifestations within this specific software ecosystem, providing a structured view of historical and current threats. The content collected here covers a broad range of vulnerability types, including cross-site scripting (XSS), information disclosure, remote code execution, and authentication bypass flaws. The time range spanned by these records extends from the early days of the software’s widespread adoption up to recent years, reflecting the evolving security landscape and remediation efforts over decades. Readers can use this aggregation to track vendor advisories and understand how specific weakness classes have impacted MediaWiki installations. It allows security professionals to examine the product’s vulnerability history, identifying patterns in exploitability and fix timelines. By reviewing these aggregated entries, users can gain insight into the overall security posture of MediaWiki, assess potential risks for their deployments, and compare the severity and frequency of different attack vectors. This resource supports informed decision-making for administrators and developers seeking to harden their wiki instances against known exploits. It emphasizes transparency by linking reported issues to their respective resolution statuses, facilitating a deeper understanding of the remediation process. Ultimately, the goal is to provide a clear, factual overview of security challenges without promoting any particular viewpoint or solution.

Vendor: mediawiki

CVE IDTitleCVSSSeverityPublished
CVE-2025-61638 Sanitizer::validateAttributes data-XSS CWE-79 6.1AIMediumAI2026-02-02
CVE-2025-61639 Suppressed blocked IP is visible in Special:BlockList, RC, and other places CWE-200 7.5AIHighAI2026-02-02
CVE-2025-61640 Stored XSS through system messages in Special:RecentChangesLinked (MW Core) CWE-79 6.1AIMediumAI2026-02-02
CVE-2025-61641 API list=allpages with maxsize is making really slow queries 9.1AICriticalAI2026-02-02
CVE-2025-61642 Stored XSS through system messages provided to CodexHtmlForms CWE-79 6.1AIMediumAI2026-02-02
CVE-2025-61643 EventStreams publishes suppressed recent change entries that are suppressed from their creation 5.3AIMediumAI2026-02-02
CVE-2025-61634 HTML rest endpoint needs PoolCounter and proper parser cache check 9.4AICriticalAI2026-02-02
CVE-2025-61636 Codex Special:Block vulnerable to message key XSS CWE-79 6.1AIMediumAI2026-02-02
CVE-2025-6589 With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hideuser' can see the hidden username in the BlockList 7.5AIHighAI2026-02-02
CVE-2025-6590 Complete content leak of private wikis due to PasswordReset Wikitext injection in error message CWE-200 7.5AIHighAI2026-02-02
CVE-2025-6591 HTML injection in API action=feedcontributions output from i18n message 8.2AIHighAI2026-02-02
CVE-2025-6593 "{{SITENAME}} registered email address has been changed" email sent to unverified email addresses 8.1AIHighAI2026-02-02
CVE-2025-6594 XSS in Special:ApiSandbox CWE-79 6.1AIMediumAI2026-02-02
CVE-2025-6597 MediaWiki should not consider autocreation as login for the purposes of security reauthentication 9.8AICriticalAI2026-02-02
CVE-2025-6927 Autoblocks from global account suppressions are publicly visible 8.2AIHighAI2026-02-02
CVE-2025-32700 AbuseFilter log interfaces expose global private and hidden filters when central DB is not available CWE-200 7.5AIHighAI2025-04-10
CVE-2025-32699 Potential javascript injection attack enabled by Unicode normalization in Action API CWE-79 9.1AICriticalAI2025-04-10
CVE-2025-32698 LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions CWE-200 7.5AIHighAI2025-04-10
CVE-2025-32697 Cascading protection is not preventing file reversions CWE-281 8.2AIHighAI2025-04-10
CVE-2025-32696 "reupload-own" restriction can be bypassed by reverting file CWE-281 7.5AIHighAI2025-04-10
CVE-2025-3469 i18n XSS vulnerability in HTMLMultiSelectField when sections are used CWE-79 6.1AIMediumAI2025-04-10
CVE-2023-3550 Stored XSS leads to privilege escalation in MediaWiki v1.40.0 CWE-79 7.3 High2023-09-25
CVE-2012-4381 MediaWiki 信任管理问题漏洞 8.1 -2020-02-08
CVE-2013-4572 MediaWiki 授权问题漏洞 9.8 -2020-02-06
CVE-2013-6451 MediaWiki 跨站脚本漏洞 6.1 -2020-01-28
CVE-2013-6455 MediaWiki CentralAuth 信息泄露漏洞 5.3 -2020-01-28
CVE-2013-4303 MediaWiki 跨站脚本漏洞 6.1 -2019-12-11
CVE-2013-1817 MediaWiki 信息泄露漏洞 7.5 -2019-11-20
CVE-2013-1816 MediaWiki 输入验证错误漏洞 7.5 -2019-11-20
CVE-2013-1951 MediaWiki 跨站脚本漏洞 6.1 -2019-10-31

All 75 known CVE vulnerabilities affecting MediaWiki with full Chinese analysis, references, and POCs where available.