All 3 CVE vulnerabilities found in AbuseFilter, with AI-generated Chinese analysis, references, and POCs.
Vendor: Wikimedia Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-58027 | QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI CWE-200 | - | - | 2026-07-01 |
| CVE-2026-34086 | AbuseFilter misuses ::userCanBitfield, exposing access-controlled information | - | - | 2026-05-11 |
| CVE-2025-6592 | Creating a permanent account from a temporary account associates temp username and IP address with real username in AbuseLog | 9.8AI | Critical AI | 2026-02-02 |
All 3 known CVE vulnerabilities affecting AbuseFilter with full Chinese analysis, references, and POCs where available.