Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

mediawiki — Vulnerabilities & Security Advisories 64

All 64 CVE vulnerabilities found in mediawiki, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation resource for the MediaWiki product, focusing on various weakness types and security tags. It collects detailed records of security flaws affecting this widely used wiki software platform, covering a broad time range from historical findings to recent disclosures. The aggregated data spans from early vulnerabilities in legacy versions up to the most recent updates, ensuring a complete timeline of security issues. Here, users can track MediaWiki vendor advisories to stay informed about official patches and remediation steps. The resource allows for a deep understanding of common weakness classes that frequently impact this software, such as cross-site scripting, injection flaws, and information disclosure. By examining these patterns, developers and security analysts can better assess risks and apply appropriate mitigations. Additionally, the page provides a historical view of vulnerabilities associated with MediaWiki, enabling users to look up the product's vulnerability history for specific versions. This chronological approach helps identify trends in security maturity and recurring issues over time. The content is structured to support thorough security audits, compliance checks, and risk assessments without overwhelming the reader with unnecessary details. All information is presented in a neutral, factual manner to facilitate efficient research and decision-making. This resource is particularly valuable for maintainers, system administrators, and security professionals who need to understand the specific threat landscape surrounding MediaWiki deployments.

Vendor: mediawiki

CVE IDTitleCVSSSeverityPublished
CVE-2025-6593 "{{SITENAME}} registered email address has been changed" email sent to unverified email addresses 8.1AIHighAI2026-02-02
CVE-2025-6594 XSS in Special:ApiSandbox CWE-79 6.1AIMediumAI2026-02-02
CVE-2025-6597 MediaWiki should not consider autocreation as login for the purposes of security reauthentication 9.8AICriticalAI2026-02-02
CVE-2025-6927 Autoblocks from global account suppressions are publicly visible 8.2AIHighAI2026-02-02
CVE-2025-32700 AbuseFilter log interfaces expose global private and hidden filters when central DB is not available CWE-200 7.5AIHighAI2025-04-10
CVE-2025-32699 Potential javascript injection attack enabled by Unicode normalization in Action API CWE-79 9.1AICriticalAI2025-04-10
CVE-2025-32698 LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions CWE-200 7.5AIHighAI2025-04-10
CVE-2025-32697 Cascading protection is not preventing file reversions CWE-281 8.2AIHighAI2025-04-10
CVE-2025-32696 "reupload-own" restriction can be bypassed by reverting file CWE-281 7.5AIHighAI2025-04-10
CVE-2025-3469 i18n XSS vulnerability in HTMLMultiSelectField when sections are used CWE-79 6.1AIMediumAI2025-04-10
CVE-2023-3550 Stored XSS leads to privilege escalation in MediaWiki v1.40.0 CWE-79 7.3 High2023-09-25
CVE-2012-4381 MediaWiki 信任管理问题漏洞 8.1 -2020-02-08
CVE-2013-4572 MediaWiki 授权问题漏洞 9.8 -2020-02-06
CVE-2013-6451 MediaWiki 跨站脚本漏洞 6.1 -2020-01-28
CVE-2013-6455 MediaWiki CentralAuth 信息泄露漏洞 5.3 -2020-01-28
CVE-2013-4303 MediaWiki 跨站脚本漏洞 6.1 -2019-12-11
CVE-2013-1817 MediaWiki 信息泄露漏洞 7.5 -2019-11-20
CVE-2013-1816 MediaWiki 输入验证错误漏洞 7.5 -2019-11-20
CVE-2013-1951 MediaWiki 跨站脚本漏洞 6.1 -2019-10-31
CVE-2012-0046 MediaWiki 信息泄露漏洞 7.5 -2019-10-29
CVE-2018-0505 BotPasswords can bypass CentralAuth's account lock 6.5 -2018-10-04
CVE-2018-0503 $wgRateLimits entry for 'user' overrides 'newbie' 4.3 -2018-10-04
CVE-2018-0504 Information disclosure in Special:Redirect/logid 6.5 -2018-10-04
CVE-2018-13258 Tarball was missing .htaccess files 5.3 -2018-10-04
CVE-2017-0365 XSS in SearchHighlighter::highlightText() [requires non-default config] 6.1 -2018-04-13
CVE-2017-0364 Special:Search allows redirects to any interwiki link 6.1 -2018-04-13
CVE-2017-0363 Special:UserLogin?returnto=interwiki:foo will redirect to external sites 6.1 -2018-04-13
CVE-2017-0362 "Mark all pages visited" on the watchlist does not require a CSRF token 8.8 -2018-04-13
CVE-2017-0361 api.log contains passwords in plaintext 7.1 -2018-04-13
CVE-2017-0366 SVG filter evasion using default attribute values in DTD declaration 5.4 -2018-04-13

All 64 known CVE vulnerabilities affecting mediawiki with full Chinese analysis, references, and POCs where available.