All 6 CVE vulnerabilities found in Mediawiki - WikiLambda Extension, with AI-generated Chinese analysis, references, and POCs.
Vendor: The Wikimedia Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-103046 | WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML CWE-79 | - | - | 2026-09-29 |
| CVE-2026-100383 | Stored i18n XSS in WikiLambda's VisualEditor integration CWE-79 | 4.8 | Medium | 2026-09-25 |
| CVE-2026-100377 | Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstract CWE-200 | 6.9 | Medium | 2026-09-25 |
| CVE-2026-96872 | WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions CWE-280 | 2.9 | Low | 2026-09-23 |
| CVE-2026-58517 | Blocked users can create and edit WikiLambda objects CWE-288 | - | - | 2026-07-01 |
| CVE-2025-62695 | Stored XSS through system messages CWE-79 | 5.4AI | Medium AI | 2025-10-21 |
All 6 known CVE vulnerabilities affecting Mediawiki - WikiLambda Extension with full Chinese analysis, references, and POCs where available.