Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 2

Found 100 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-0668 VisualData extension: Regular Expression Denial of Service (ReDoS) via crafted user input Wikimedia FoundationMediaWiki - VisualData Extension 中危 -2026-01-07 17:36:19 Deep Dive
CVE-2025-62659 The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors The Wikimedia FoundationMediaWiki CookieConsent extension--2025-10-22 15:31:29 Deep Dive
CVE-2025-62661 Do permission checking when getting counts of global and local edits, new articles and thanks The Wikimedia FoundationMediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension--2025-10-21 19:33:26 Deep Dive
CVE-2025-12004 The compare API module breaks Extension:Lockdown The Wikimedia FoundationMediawiki - Lockdown Extension--2025-10-21 06:20:04 Deep Dive
CVE-2025-62702 Stored XSS through system messages The Wikimedia FoundationMediawiki - PageTriage Extension--2025-10-21 04:42:28 Deep Dive
CVE-2025-62694 Stored XSS through a system message The Wikimedia FoundationMediawiki - WikiLove Extension--2025-10-21 04:28:15 Deep Dive
CVE-2025-62695 Stored XSS through system messages The Wikimedia FoundationMediawiki - WikiLambda Extension--2025-10-21 04:02:01 Deep Dive
CVE-2025-62696 Multiple critical security issues in Springboard The Wikimedia FoundationMediawiki Foundation - Springboard Extension--2025-10-21 03:58:06 Deep Dive
CVE-2025-62699 Special:Translate tool does not use the correct IP and User-Agent in the CheckUser tool The Wikimedia FoundationMediawiki - Translate Extension--2025-10-21 03:48:50 Deep Dive
CVE-2025-62658 SQL injection in WatchAnalytics through Special:ClearPendingReviews The Wikimedia FoundationMediaWiki WatchAnalytics extension--2025-10-20 20:23:22 Deep Dive
CVE-2025-62657 Stored XSS through system messages in PageForms The Wikimedia FoundationMediaWiki PageForms extension--2025-10-20 20:19:33 Deep Dive
CVE-2025-62656 GlobalBlocking Special:GlobalBlockList vulnerable to message key stored XSS The Wikimedia FoundationMediaWiki GlobalBlocking extension--2025-10-20 20:15:15 Deep Dive
CVE-2025-62697 Improperly sanitized style parameter in LanguageSelector The Wikimedia FoundationMediawiki - LanguageSelector Extension--2025-10-20 19:27:04 Deep Dive
CVE-2025-62693 Stored XSS through system messages in LastModified The Wikimedia FoundationMediawiki - LastModified Extension--2025-10-20 17:51:29 Deep Dive
CVE-2025-11937 Stored XSS through a system message in SecurePoll The Wikimedia FoundationMediawiki - SecurePoll Extension--2025-10-18 05:14:56 Deep Dive
CVE-2025-62666 DoS vector through the cirrusbuilddoc query API The Wikimedia FoundationMediawiki - CirrusSearch Extension--2025-10-18 04:47:52 Deep Dive
CVE-2025-62667 Stored XSS through article extracts in GrowthExperiments The Wikimedia FoundationMediawiki - GrowthExperiments Extension--2025-10-18 04:42:31 Deep Dive
CVE-2025-62668 Insufficient permission checks in action=growthsetmentor The Wikimedia FoundationMediawiki - GrowthExperiments Extension--2025-10-18 04:39:28 Deep Dive
CVE-2025-62669 UserInfoCard: activeLocalBlocksAllWikis does not do permissions checks The Wikimedia FoundationMediawiki - CentralAuth Extension--2025-10-18 04:34:35 Deep Dive
CVE-2025-62670 Stored XSS through a system message in FlexDiagrams The Wikimedia FoundationMediawiki - FlexDiagrams Extension--2025-10-18 04:29:48 Deep Dive