Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Wikimedia Foundation — Vulnerabilities & Security Advisories 136

Browse all 136 CVE security advisories affecting Wikimedia Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Wikimedia Foundation operates the world’s largest collaborative encyclopedia platform, hosting Wikipedia and related projects that serve billions of monthly visitors. Its infrastructure relies on complex software stacks, including MediaWiki, which has historically been susceptible to various vulnerability classes. Common issues include cross-site scripting (XSS), SQL injection, and remote code execution (RCE) stemming from legacy code paths or misconfigurations. While the organization maintains a robust security posture with regular audits and bug bounty programs, the sheer scale of its codebase and the open nature of its editing model present unique challenges. Recent years have seen efforts to mitigate privilege escalation risks and improve input validation. Despite these ongoing technical hurdles, the Foundation remains a critical public resource, balancing transparency with the need to protect user data and system integrity against sophisticated cyber threats targeting its extensive digital footprint.

Found 55 results / 136 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-61638 Sanitizer::validateAttributes data-XSS — MediaWiki CWE-79 6.1AI Medium AI 2026-02-02
CVE-2025-61639 Suppressed blocked IP is visible in Special:BlockList, RC, and other places — MediaWiki CWE-200 7.5AI High AI 2026-02-02
CVE-2025-61640 Stored XSS through system messages in Special:RecentChangesLinked (MW Core) — MediaWiki CWE-79 6.1AI Medium AI 2026-02-02
CVE-2025-61641 API list=allpages with maxsize is making really slow queries — MediaWiki 9.1AI Critical AI 2026-02-02
CVE-2025-61642 Stored XSS through system messages provided to CodexHtmlForms — MediaWiki CWE-79 6.1AI Medium AI 2026-02-02
CVE-2025-61643 EventStreams publishes suppressed recent change entries that are suppressed from their creation — MediaWiki 5.3AI Medium AI 2026-02-02
CVE-2025-61634 HTML rest endpoint needs PoolCounter and proper parser cache check — MediaWiki 9.4AI Critical AI 2026-02-02
CVE-2025-61636 Codex Special:Block vulnerable to message key XSS — MediaWiki CWE-79 6.1AI Medium AI 2026-02-02
CVE-2025-6589 With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hideuser' can see the hidden username in the BlockList — MediaWiki 7.5AI High AI 2026-02-02
CVE-2025-6590 Complete content leak of private wikis due to PasswordReset Wikitext injection in error message — MediaWiki CWE-200 7.5AI High AI 2026-02-02
CVE-2025-6591 HTML injection in API action=feedcontributions output from i18n message — MediaWiki 8.2AI High AI 2026-02-02
CVE-2025-6593 "{{SITENAME}} registered email address has been changed" email sent to unverified email addresses — MediaWiki 8.1AI High AI 2026-02-02
CVE-2025-6594 XSS in Special:ApiSandbox — MediaWiki CWE-79 6.1AI Medium AI 2026-02-02
CVE-2025-6597 MediaWiki should not consider autocreation as login for the purposes of security reauthentication — MediaWiki 9.8AI Critical AI 2026-02-02
CVE-2025-6927 Autoblocks from global account suppressions are publicly visible — MediaWiki 8.2AI High AI 2026-02-02
CVE-2025-32700 AbuseFilter log interfaces expose global private and hidden filters when central DB is not available — MediaWiki CWE-200 7.5AI High AI 2025-04-10
CVE-2025-32699 Potential javascript injection attack enabled by Unicode normalization in Action API — MediaWiki CWE-79 9.1AI Critical AI 2025-04-10
CVE-2025-32698 LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions — MediaWiki CWE-200 7.5AI High AI 2025-04-10
CVE-2025-32697 Cascading protection is not preventing file reversions — MediaWiki CWE-281 8.2AI High AI 2025-04-10
CVE-2025-32696 "reupload-own" restriction can be bypassed by reverting file — MediaWiki CWE-281 7.5AI High AI 2025-04-10
CVE-2025-3469 i18n XSS vulnerability in HTMLMultiSelectField when sections are used — MediaWiki CWE-79 6.1AI Medium AI 2025-04-10
CVE-2013-4572 MediaWiki 授权问题漏洞 — MediaWiki 9.8 - 2020-02-06
CVE-2013-6451 MediaWiki 跨站脚本漏洞 — MediaWiki 6.1 - 2020-01-28
CVE-2013-6455 MediaWiki CentralAuth 信息泄露漏洞 — MediaWiki 5.3 - 2020-01-28
CVE-2013-4303 MediaWiki 跨站脚本漏洞 — MediaWiki 6.1 - 2019-12-11

This page lists every published CVE security advisory associated with Wikimedia Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.