Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Associated Vulnerability
Found 201 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-10354 Reflected Cross-Site Scripting (XSS) in Semantic MediaWiki Semantic MediaWikiSemantic MediaWiki--2026-04-21 14:42:38 Deep Dive
CVE-2026-39936 Stored XSS in Score due to usage of non-reserved data attributes The Wikimedia FoundationMediawiki - Score Extension--2026-04-07 22:11:04 Deep Dive
CVE-2026-39935 XSS-via-i18n in localised wiki names The Wikimedia FoundationMediawiki - CampaignEvents Extension--2026-04-07 22:04:02 Deep Dive
CVE-2026-39934 Growth Experiments ReassignMenteesJob runs as an infinite loop The Wikimedia FoundationMediawiki - GrowthExperiments Extension--2026-04-07 22:00:46 Deep Dive
CVE-2026-39933 Multiple XSS vulnerabilities in GlobalWatchlist The Wikimedia FoundationMediawiki - GlobalWatchlist Extension--2026-04-07 21:51:55 Deep Dive
CVE-2026-39937 Global vanishing does not completely remove user email The Wikimedia FoundationMediawiki - CentralAuth Extension--2026-04-07 21:44:47 Deep Dive
CVE-2026-39837 Stored XSS through the dynamic table format in Cargo Wikimedia FoundationMediawiki - Cargo Extension--2026-04-07 19:47:18 Deep Dive
CVE-2026-39841 Stored XSS through list fields on Cargo's page values and Special:CargoTables Wikimedia FoundationMediawiki - Cargo Extension--2026-04-07 19:43:48 Deep Dive
CVE-2026-39840 CSS injection in multiple Cargo display formats Wikimedia FoundationMediawiki - Cargo Extension--2026-04-07 19:35:36 Deep Dive
CVE-2026-39839 Stored XSS through URLs in Cargo's map format Wikimedia FoundationMediawiki - Cargo Extension--2026-04-07 19:29:11 Deep Dive
CVE-2026-39838 ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSS Wikimedia FoundationMediaWiki - ProofreadPage Extension--2026-04-07 19:17:52 Deep Dive
CVE-2026-5762 ReportIncident DiscussionTools integration causes slow requests Wikimedia FoundationMediaWiki - ReportIncident Extension--2026-04-07 18:42:35 Deep Dive
CVE-2026-22711 Stored XSS through system messages in WikiLove The Wikimedia FoundationMediawiki - Wikilove Extension--2026-04-07 18:39:37 Deep Dive
CVE-2026-30917 Stored XSS on Bucket namespace pages weirdgloopmediawiki-extensions-Bucket--2026-03-09 22:50:21 Deep Dive
CVE-2025-67481 mw.message(…).parse() doesn't output safe HTML, but it's being used as if it does Wikimedia FoundationMediaWiki--2026-02-03 01:30:40 Deep Dive
CVE-2025-67483 Theoretical i18n XSS in mediawiki.page.preview.js when a page has multiple protection levels Wikimedia FoundationMediaWiki--2026-02-03 01:26:28 Deep Dive
CVE-2025-67484 Action API xslt option allows JavaScript execution by administrators who are not interface administrators Wikimedia FoundationMediaWiki--2026-02-03 01:24:56 Deep Dive
CVE-2025-67480 list=allrevisions can be used to bypass Extension:Lockdown Wikimedia FoundationMediaWiki--2026-02-03 01:23:02 Deep Dive
CVE-2025-67475 Stored XSS through edit summaries in MW Core Wikimedia FoundationMediaWiki--2026-02-03 01:21:09 Deep Dive
CVE-2025-67476 Importing leaks IP address of importer via EventStreams Wikimedia FoundationMediaWiki--2026-02-03 01:18:55 Deep Dive