Wikimedia Foundation Mediawiki vulnerabilities

38 known vulnerabilities affecting wikimedia_foundation/mediawiki.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4LOW11

Vulnerabilities

Page 1 of 2
CVE-2025-61643LOWCVSS 2.7≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61643 [LOW] CWE-212 CVE-2025-61643: Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
nvd
CVE-2025-61646LOWCVSS 1.2≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61646 [LOW] CWE-22 CVE-2025-61646: Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
nvd
CVE-2025-67476LOWCVSS 1.3≥ *, < 1.44.3, 1.45.12026-02-03
CVE-2025-67476 [LOW] CVE-2025-67476: Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php. This issue affects MediaWiki: from * before 1.44.3, 1.45.1.
nvd
CVE-2025-61641LOWCVSS 1.7≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61641 [LOW] CWE-22 CVE-2025-61641: Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
nvd
CVE-2025-61639LOWCVSS 1.7≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61639 [LOW] CWE-200 CVE-2025-61639: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Med Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/ManualLogEntry.Php, includes/recentchanges/RecentChangeFactory.Php, includes/recentchanges/RecentChangeStore.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1
nvd
CVE-2025-61638UNKNOWNCVSS 0.0≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61638 [NONE] CWE-79 CVE-2025-61638: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoi
nvd
CVE-2025-61642UNKNOWNCVSS 0.0≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61642 [NONE] CWE-79 CVE-2025-61642: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
nvd
CVE-2025-61636UNKNOWNCVSS 0.0≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61636 [NONE] CWE-79 CVE-2025-61636: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
nvd
CVE-2025-67480UNKNOWNCVSS 0.0≥ *, < 1.39.16, 1.43.6, 1.44.3, 1.45.12026-02-03
CVE-2025-67480 [NONE] CWE-20 CVE-2025-67480: Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
nvd
CVE-2025-67477UNKNOWNCVSS 0.0≥ *, < 1.44.3, 1.45.12026-02-03
CVE-2025-67477 [NONE] CWE-79 CVE-2025-67477: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js. This issue affects MediaWiki: from * before 1.44.3, 1.45.1.
nvd
CVE-2025-67484UNKNOWNCVSS 0.0≥ *, < 1.39.16, 1.43.6, 1.44.3, 1.45.12026-02-03
CVE-2025-67484 [NONE] CWE-20 CVE-2025-67484: Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
nvd
CVE-2025-11261UNKNOWNCVSS 0.0≥ *, < 1.39.15, 1.43.5, 1.44.22026-02-03
CVE-2025-11261 [NONE] CWE-79 CVE-2025-11261: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Language/mediawiki.Language.Js. This issue affects MediaWiki: from * before 1.39.15, 1.43.5, 1.44.2.
nvd
CVE-2025-61637UNKNOWNCVSS 0.0≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61637 [NONE] CWE-79 CVE-2025-61637: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Action/mediawiki.Action.Edit.Preview.Js, resources/src/mediawiki.Page.Preview.Js. This issue affects MediaWiki: from * before 1.39.14, 1
nvd
CVE-2025-61634UNKNOWNCVSS 0.0≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61634 [NONE] CWE-22 CVE-2025-61634: Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
nvd
CVE-2025-67475UNKNOWNCVSS 0.0≥ *, < 1.39.16, 1.43.6, 1.44.3, 1.45.12026-02-03
CVE-2025-67475 [NONE] CWE-79 CVE-2025-67475: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/CommentFormatter/CommentParser.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
nvd
CVE-2025-67479UNKNOWNCVSS 0.0≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-67479 [NONE] CVE-2025-67479: Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Cite. This vulnerability is as Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Cite. This vulnerability is associated with program files includes/Parser/CoreParserFunctions.Php, includes/Parser/Sanitizer.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Cite: from * before 1.39.14, 1.43.4, 1.44.1.
nvd
CVE-2025-67481UNKNOWNCVSS 0.0≥ *, < 1.39.16, 1.43.6, 1.44.3, 1.45.12026-02-03
CVE-2025-67481 [NONE] CWE-79 CVE-2025-67481: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.JqueryMsg/mediawiki.JqueryMsg.Js. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
nvd
CVE-2025-67483UNKNOWNCVSS 0.0≥ *, < 1.43.6, 1.44.3, 1.45.12026-02-03
CVE-2025-67483 [NONE] CWE-79 CVE-2025-67483: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Page.Preview.Js. This issue affects MediaWiki: from * before 1.43.6, 1.44.3, 1.45.1.
nvd
CVE-2025-61645UNKNOWNCVSS 0.0≥ *, < 1.44.12026-02-03
CVE-2025-61645 [NONE] CWE-79 CVE-2025-61645: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/pager/CodexTablePager.Php. This issue affects MediaWiki: from * before 1.44.1.
nvd
CVE-2025-61640UNKNOWNCVSS 0.0≥ *, < 1.39.14, 1.43.4, 1.44.12026-02-03
CVE-2025-61640 [NONE] CWE-79 CVE-2025-61640: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/RclToOrFromWidget.Js. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
nvd