Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 11

Found 2767 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-61646 Watchlist group mode reveals authors of edits with hidden authorship Wikimedia FoundationMediaWiki--2026-02-03 00:11:29 Deep Dive
CVE-2025-61647 UserInfoCard: Don't allow access to information about users who are suppressed if you don't have suppressor rights Wikimedia FoundationCheckUser--2026-02-03 00:02:04 Deep Dive
CVE-2025-61644 i18n XSS through Special:Watchlist Wikimedia FoundationMediaWiki--2026-02-02 23:57:18 Deep Dive
CVE-2025-61637 Stored XSS through system messages in MW Core Wikimedia FoundationMediaWiki--2026-02-02 23:54:04 Deep Dive
CVE-2025-61638 Sanitizer::validateAttributes data-XSS Wikimedia FoundationMediaWiki--2026-02-02 23:52:10 Deep Dive
CVE-2025-61639 Suppressed blocked IP is visible in Special:BlockList, RC, and other places Wikimedia FoundationMediaWiki--2026-02-02 23:48:03 Deep Dive
CVE-2025-61640 Stored XSS through system messages in Special:RecentChangesLinked (MW Core) Wikimedia FoundationMediaWiki--2026-02-02 23:42:04 Deep Dive
CVE-2025-61641 API list=allpages with maxsize is making really slow queries Wikimedia FoundationMediaWiki--2026-02-02 23:39:39 Deep Dive
CVE-2025-61642 Stored XSS through system messages provided to CodexHtmlForms Wikimedia FoundationMediaWiki--2026-02-02 23:36:43 Deep Dive
CVE-2025-61643 EventStreams publishes suppressed recent change entries that are suppressed from their creation Wikimedia FoundationMediaWiki--2026-02-02 23:33:50 Deep Dive
CVE-2025-61634 HTML rest endpoint needs PoolCounter and proper parser cache check Wikimedia FoundationMediaWiki--2026-02-02 23:28:54 Deep Dive
CVE-2025-61635 Add rate limiting to ApiFancyCaptchaReload Wikimedia FoundationConfirmEdit--2026-02-02 23:26:15 Deep Dive
CVE-2025-61636 Codex Special:Block vulnerable to message key XSS Wikimedia FoundationMediaWiki--2026-02-02 23:23:27 Deep Dive
CVE-2025-6589 With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hideuser' can see the hidden username in the BlockList Wikimedia FoundationMediaWiki--2026-02-02 23:03:46 Deep Dive
CVE-2025-6590 Complete content leak of private wikis due to PasswordReset Wikitext injection in error message Wikimedia FoundationMediaWiki--2026-02-02 23:03:08 Deep Dive
CVE-2025-6591 HTML injection in API action=feedcontributions output from i18n message Wikimedia FoundationMediaWiki--2026-02-02 23:02:34 Deep Dive
CVE-2025-6592 Creating a permanent account from a temporary account associates temp username and IP address with real username in AbuseLog Wikimedia FoundationAbuseFilter--2026-02-02 23:02:13 Deep Dive
CVE-2025-6593 "{{SITENAME}} registered email address has been changed" email sent to unverified email addresses Wikimedia FoundationMediaWiki--2026-02-02 23:01:29 Deep Dive
CVE-2025-6594 XSS in Special:ApiSandbox Wikimedia FoundationMediaWiki--2026-02-02 23:00:58 Deep Dive
CVE-2025-6595 MediaWiki 安全漏洞 Wikimedia FoundationMultimediaViewer--2026-02-02 22:59:43 Deep Dive