Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 201 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-6597 MediaWiki should not consider autocreation as login for the purposes of security reauthentication Wikimedia FoundationMediaWiki--2026-02-02 22:57:30 Deep Dive
CVE-2025-6927 Autoblocks from global account suppressions are publicly visible Wikimedia FoundationMediaWiki--2026-02-02 22:55:09 Deep Dive
CVE-2025-11175 DiscussionTools should use better regex The Wikimedia FoundationMediawiki - DiscussionTools Extension--2026-01-30 19:12:07 Deep Dive
CVE-2026-0817 CampaignEvents API missing authorization exposes meeting and chat URLs Wikimedia FoundationMediaWiki - CampaignEvents extension 中危 -2026-01-09 15:50:51 Deep Dive
CVE-2026-22712 ApprovedRevs allows bypassing the inline CSS sanitizer The Wikimedia FoundationMediawiki - ApprovedRevs Extension 中危 -2026-01-09 00:06:22 Deep Dive
CVE-2026-22713 Stored XSS through edit summaries in GrowthExperiments The Wikimedia FoundationMediawiki - GrowthExperiments Extension 中危 -2026-01-09 00:00:58 Deep Dive
CVE-2026-22714 i18n XSS, DoS and config SQLI in Monaco The Wikimedia FoundationMediawiki - Monaco Skin 中危 -2026-01-08 23:56:07 Deep Dive
CVE-2026-22710 Stored XSS through autocomment system messages in Wikibase The Wikimedia FoundationMediawiki - Wikibase Extension 中危 -2026-01-08 23:48:52 Deep Dive
CVE-2026-0671 Multiple stored i18n/message-key XSSes in UploadWizard Wikimedia FoundationMediaWiki - UploadWizard extension 中危 -2026-01-08 16:21:24 Deep Dive
CVE-2026-0670 Stored XSS through a system message and a user-provided parameter in ProofreadPage Wikimedia FoundationMediaWiki - ProofreadPage Extension 中危 -2026-01-07 18:55:43 Deep Dive
CVE-2026-0669 Path Traversal vulnerability in CSS extension on certain web servers Wikimedia FoundationMediaWiki - CSS extension 中危 -2026-01-07 17:46:57 Deep Dive
CVE-2026-0668 VisualData extension: Regular Expression Denial of Service (ReDoS) via crafted user input Wikimedia FoundationMediaWiki - VisualData Extension 中危 -2026-01-07 17:36:19 Deep Dive
CVE-2025-62659 The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors The Wikimedia FoundationMediaWiki CookieConsent extension--2025-10-22 15:31:29 Deep Dive
CVE-2025-62661 Do permission checking when getting counts of global and local edits, new articles and thanks The Wikimedia FoundationMediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension--2025-10-21 19:33:26 Deep Dive
CVE-2025-12004 The compare API module breaks Extension:Lockdown The Wikimedia FoundationMediawiki - Lockdown Extension--2025-10-21 06:20:04 Deep Dive
CVE-2025-62701 Stored XSS through system messages The Wikimedia FoundationMediawiki - Wikistories--2025-10-21 04:45:05 Deep Dive
CVE-2025-62702 Stored XSS through system messages The Wikimedia FoundationMediawiki - PageTriage Extension--2025-10-21 04:42:28 Deep Dive
CVE-2025-62694 Stored XSS through a system message The Wikimedia FoundationMediawiki - WikiLove Extension--2025-10-21 04:28:15 Deep Dive
CVE-2025-62695 Stored XSS through system messages The Wikimedia FoundationMediawiki - WikiLambda Extension--2025-10-21 04:02:01 Deep Dive
CVE-2025-62696 Multiple critical security issues in Springboard The Wikimedia FoundationMediawiki Foundation - Springboard Extension--2025-10-21 03:58:06 Deep Dive