mediawiki
431 tracked vulnerabilities.
CVE-2025-61646
MEDIUM
MediaWiki <1.39.14-1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-61645
MEDIUM
MediaWiki < 1.44.1 - Cross-Site Scripting in CodexTablePager
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-11261
MEDIUM
MediaWiki < 1.39.15, 1.43.5, 1.44.2 - Cross-Site Scripting in mediawiki.Language.Js
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61643
MEDIUM
MediaWiki <1.39.14, 1.43.4, 1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61642
MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in HTMLForm Code
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61641
MEDIUM
MediaWiki <1.39.14, 1.43.4, 1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61640
MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in RclToOrFromWidget
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61639
MEDIUM
MediaWiki <1.39.14-1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61638
MEDIUM
MediaWiki <1.39.14, 1.43.4, 1.44.1 - XSS
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61637
MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in Edit Preview
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61636
MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in HTMLButtonField
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61634
LOW
MediaWiki <1.39.14, 1.43.4, 1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-62671
MEDIUM
MediaWiki Cargo Extension < 3.8.3 - Stored Cross-Site Scripting
Oct 18, 2025
EPSS 0.00
CVE-2025-23081
MEDIUM
MediaWiki DataTransfer Extension 1.39.0-1.39.10, 1.41.0-1.41.2, 1.42.0-1.42.1 - CSRF and XSS
Jan 14, 2025
CVSS 6.1
EPSS 0.00
CVE-2024-47849
CRITICAL
Mediawiki - Cargo <3.6.1 - SQL Injection
Oct 05, 2024
CVSS 9.8
EPSS 0.01
CVE-2024-47847
MEDIUM
The Wikimedia Foundation Mediawiki - Cargo <3.6.1 - XSS
Oct 05, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-47846
HIGH
Mediawiki Cargo 3.6.X < 3.6.1 - Cross-Site Request Forgery
Oct 05, 2024
CVSS 8.8
EPSS 0.01
CVE-2024-47913
MEDIUM
MediaWiki AbuseFilter <1.39.9, 1.40.x-1.41.x<1.41.3, 1.42.x<1.42.2 - API Unauthorized Log Disclosure
Oct 04, 2024
CVSS 5.3
EPSS 0.01
CVE-2024-40605
MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting via Foreground Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40604
MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting via Nimbus Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40603
MEDIUM
MediaWiki < 1.42.1 - Cross-Site Request Forgery via Special:ChangeRating
Jul 07, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-40602
MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting in Tempo Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40601
MEDIUM
MediaWiki < 1.42.1 - Cross-Site Request Forgery in MediaWikiChat Extension API Modules
Jul 07, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-40600
MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting in Metrolook Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40599
MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting in GuMaxDD Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters