Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 201 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-62699 Special:Translate tool does not use the correct IP and User-Agent in the CheckUser tool The Wikimedia FoundationMediawiki - Translate Extension--2025-10-21 03:48:50 Deep Dive
CVE-2025-62658 SQL injection in WatchAnalytics through Special:ClearPendingReviews The Wikimedia FoundationMediaWiki WatchAnalytics extension--2025-10-20 20:23:22 Deep Dive
CVE-2025-62657 Stored XSS through system messages in PageForms The Wikimedia FoundationMediaWiki PageForms extension--2025-10-20 20:19:33 Deep Dive
CVE-2025-62656 GlobalBlocking Special:GlobalBlockList vulnerable to message key stored XSS The Wikimedia FoundationMediaWiki GlobalBlocking extension--2025-10-20 20:15:15 Deep Dive
CVE-2025-62697 Improperly sanitized style parameter in LanguageSelector The Wikimedia FoundationMediawiki - LanguageSelector Extension--2025-10-20 19:27:04 Deep Dive
CVE-2025-62698 Stored XSS through system messages in ExternalGuidance The Wikimedia FoundationMediawiki - ExternalGuidance--2025-10-20 18:07:46 Deep Dive
CVE-2025-62700 Stored XSS through a system message in MultiBoilerplate The Wikimedia FoundationMediawiki - MultiBoilerplate Extensionmaste--2025-10-20 17:53:53 Deep Dive
CVE-2025-62693 Stored XSS through system messages in LastModified The Wikimedia FoundationMediawiki - LastModified Extension--2025-10-20 17:51:29 Deep Dive
CVE-2025-11937 Stored XSS through a system message in SecurePoll The Wikimedia FoundationMediawiki - SecurePoll Extension--2025-10-18 05:14:56 Deep Dive
CVE-2025-62666 DoS vector through the cirrusbuilddoc query API The Wikimedia FoundationMediawiki - CirrusSearch Extension--2025-10-18 04:47:52 Deep Dive
CVE-2025-62667 Stored XSS through article extracts in GrowthExperiments The Wikimedia FoundationMediawiki - GrowthExperiments Extension--2025-10-18 04:42:31 Deep Dive
CVE-2025-62668 Insufficient permission checks in action=growthsetmentor The Wikimedia FoundationMediawiki - GrowthExperiments Extension--2025-10-18 04:39:28 Deep Dive
CVE-2025-62669 UserInfoCard: activeLocalBlocksAllWikis does not do permissions checks The Wikimedia FoundationMediawiki - CentralAuth Extension--2025-10-18 04:34:35 Deep Dive
CVE-2025-62670 Stored XSS through a system message in FlexDiagrams The Wikimedia FoundationMediawiki - FlexDiagrams Extension--2025-10-18 04:29:48 Deep Dive
CVE-2025-62671 Stored XSS through wikitext in Cargo The Wikimedia FoundationMediawiki - Cargo Extension--2025-10-18 04:24:36 Deep Dive
CVE-2025-62662 Stored XSS through system messages in AdvancedSearch The Wikimedia FoundationMediawiki - AdvancedSearch Extension--2025-10-18 04:19:31 Deep Dive
CVE-2025-62663 Stored XSS through a system message in UploadWizard The Wikimedia FoundationMediawiki - UploadWizard Extension--2025-10-18 04:16:01 Deep Dive
CVE-2025-62664 Stored XSS through a system message in ImageRating The Wikimedia FoundationMediawiki - ImageRating Extension--2025-10-18 04:13:27 Deep Dive
CVE-2025-62665 Stored XSS through system messages in Skin:BlueSky Wikimedia FoundationMediawiki - Skin:BlueSky--2025-10-18 04:10:27 Deep Dive
CVE-2025-62655 SQL injection in Cargo via Special:CargoExport The Wikimedia FoundationMediaWiki Cargo extension--2025-10-17 22:46:29 Deep Dive