Wikimedia Vector是Wikimedia基金会的一个桌面端界面外观。 Wikimedia Vector存在安全漏洞,该漏洞源于对网页生成期间输入的中和不当,可能导致跨站脚本。以下版本受到影响:1.40.0至1.42.7之前版本、1.43.2版本和1.44.0版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Wikimedia Foundation | Vector | >= 1.40.0 ~ 1.42.7, 1.43.2, 1.44.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-61636 | Codex Special:Block vulnerable to message key XSS | |
| CVE-2025-61642 | Stored XSS through system messages provided to CodexHtmlForms | |
| CVE-2025-61644 | i18n XSS through Special:Watchlist | |
| CVE-2025-61643 | EventStreams publishes suppressed recent change entries that are suppressed from their cre | |
| CVE-2025-61641 | API list=allpages with maxsize is making really slow queries | |
| CVE-2025-61638 | Sanitizer::validateAttributes data-XSS | |
| CVE-2025-61634 | HTML rest endpoint needs PoolCounter and proper parser cache check | |
| CVE-2025-61640 | Stored XSS through system messages in Special:RecentChangesLinked (MW Core) | |
| CVE-2025-61637 | Stored XSS through system messages in MW Core | |
| CVE-2025-61639 | Suppressed blocked IP is visible in Special:BlockList, RC, and other places | |
| CVE-2025-6594 | XSS in Special:ApiSandbox | |
| CVE-2025-61635 | Add rate limiting to ApiFancyCaptchaReload | |
| CVE-2025-6591 | HTML injection in API action=feedcontributions output from i18n message | |
| CVE-2025-6595 | MediaWiki 安全漏洞 | |
| CVE-2025-6592 | Creating a permanent account from a temporary account associates temp username and IP addr | |
| CVE-2025-6927 | Autoblocks from global account suppressions are publicly visible | |
| CVE-2025-6597 | MediaWiki should not consider autocreation as login for the purposes of security reauthent | |
| CVE-2025-6593 | "{{SITENAME}} registered email address has been changed" email sent to unverified email ad | |
| CVE-2025-6589 | With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hi | |
| CVE-2025-6590 | Complete content leak of private wikis due to PasswordReset Wikitext injection in error me |
No comments yet