All 4 CVE vulnerabilities found in Mediawiki - CentralAuth Extension, with AI-generated Chinese analysis, references, and POCs.
Vendor: Wikimedia Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-100244 | CentralAuth exposes locally suppressed block information via globaluserinfo API and Special:CentralAuth (incomplete fix for CVE-2025-62669) CWE-200 | - | - | 2026-09-29 |
| CVE-2026-39937 | Global vanishing does not completely remove user email CWE-212 | 7.5AI | High AI | 2026-04-07 |
| CVE-2025-62669 | UserInfoCard: activeLocalBlocksAllWikis does not do permissions checks CWE-200 | 7.5AI | High AI | 2025-10-18 |
| CVE-2025-6926 | Security Authentication Bypass in CentralAuth CWE-287 | 9.8AI | Critical AI | 2025-07-03 |
All 4 known CVE vulnerabilities affecting Mediawiki - CentralAuth Extension with full Chinese analysis, references, and POCs where available.