CVE-2025-62655

LOW

MediaWiki Cargo <1.44 - SQL Injection

Title source: llm
STIX 2.1

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects MediaWiki Cargo extension: 1.39, 1.43, 1.44.

References (1)

Core 1
Core References

Scores

CVSS v4 2.1
EPSS 0.0025
EPSS Percentile 16.0%
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Amber

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (3)
The Wikimedia Foundation/MediaWiki Cargo extension 1.39
The Wikimedia Foundation/MediaWiki Cargo extension 1.43
The Wikimedia Foundation/MediaWiki Cargo extension 1.44
Published Oct 17, 2025
Tracked Since Feb 18, 2026