Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Wikimedia Foundation — Vulnerabilities & Security Advisories 136

Browse all 136 CVE security advisories affecting Wikimedia Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Wikimedia Foundation operates the world’s largest collaborative encyclopedia platform, hosting Wikipedia and related projects that serve billions of monthly visitors. Its infrastructure relies on complex software stacks, including MediaWiki, which has historically been susceptible to various vulnerability classes. Common issues include cross-site scripting (XSS), SQL injection, and remote code execution (RCE) stemming from legacy code paths or misconfigurations. While the organization maintains a robust security posture with regular audits and bug bounty programs, the sheer scale of its codebase and the open nature of its editing model present unique challenges. Recent years have seen efforts to mitigate privilege escalation risks and improve input validation. Despite these ongoing technical hurdles, the Foundation remains a critical public resource, balancing transparency with the need to protect user data and system integrity against sophisticated cyber threats targeting its extensive digital footprint.

CVE IDTitleCVSSSeverityPublished
CVE-2026-58025 Remote Code Execution via Unsafe Deserialization in LogItem Import — MediaWikiCWE-502--2026-07-01
CVE-2026-58029 Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata — MediaWiki--2026-07-01
CVE-2026-58028 Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets — MediaWikiCWE-79--2026-07-01
CVE-2026-58026 $wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces — MediaWikiCWE-200--2026-07-01
CVE-2026-8857 Full RCE using EasyTimeline Extension — timelineCWE-94--2026-07-01
CVE-2026-58038 Stored XSS through javascript URLs in SVGs generated by EasyTimeline — timelineCWE-79--2026-07-01
CVE-2026-58027 QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI — AbuseFilterCWE-200--2026-07-01
CVE-2026-58030 SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute — SyntaxHighlight_GeSHiCWE-79--2026-07-01
CVE-2026-58032 mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html — MediaWikiCWE-79--2026-07-01
CVE-2026-58033 "Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted — MediaWikiCWE-200--2026-07-01
CVE-2026-58037 Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input — MediaWikiCWE-79--2026-07-01
CVE-2026-58036 Users API leaks whether privileged users have their user groups disabled for lack of 2FA — MediaWikiCWE-200--2026-07-01
CVE-2026-58024 API identification of users on private wikis — MediaWikiCWE-200--2026-07-01
CVE-2026-13707 Session fixation attacks on improperly configured OAuth 1.0a tools — OAuthCWE-384--2026-07-01
CVE-2026-13706 UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG — UrlShortenerCWE-20--2026-07-01
CVE-2026-58031 Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected — MediaWikiCWE-79--2026-07-01
CVE-2026-58034 Stored XSS through a system message when blocking a temporary account that's related to other temporary accounts — CheckUserCWE-79--2026-07-01
CVE-2026-58035 Stored XSS through a system message in the codex version of Special:Block — MediaWikiCWE-79--2026-07-01
CVE-2026-5266 Wikimedia Echo 信息泄露漏洞 — EchoCWE-200--2026-05-11
CVE-2026-34095 action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request — MediaWiki--2026-05-11
CVE-2026-34094 Customized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefix — MediaWiki--2026-05-11
CVE-2026-34093 Special:UserRights allows viewing user rights from private wiki — MediaWikiCWE-200--2026-05-11
CVE-2026-34092 Block UI elements in 'tools'-sidebar shows presence of an autoblocked IP — MediaWikiCWE-200--2026-05-11
CVE-2026-34091 User localization leaked by AbuseFilter + EventStream — MediaWikiCWE-200--2026-05-11
CVE-2026-34090 Suggested investigations: Handle suppressed usernames — CheckUserCWE-200--2026-05-11
CVE-2026-34089 Memory leak in Scribunto causes runJobs.php to run out of memory — Scribunto--2026-05-11
CVE-2026-34088 RecentChanges entries expose suppressed content via generated log page html — MediaWikiCWE-200--2026-05-11
CVE-2026-34087 Users API leaks whether privileged users have their user groups disabled for lack of 2FA — OATHAuthCWE-200--2026-05-11
CVE-2026-34086 AbuseFilter misuses ::userCanBitfield, exposing access-controlled information — AbuseFilter--2026-05-11
CVE-2026-39837 Stored XSS through the dynamic table format in Cargo — Mediawiki - Cargo ExtensionCWE-80 6.1AIMediumAI2026-04-07

This page lists every published CVE security advisory associated with Wikimedia Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.