<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – MediaWiki</title>
  <link>https://cvedaily.com/pages/tags/mediawiki.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mediawiki.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – MediaWiki</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-34095 – Vulnerability in Wikimedia Foundation MediaWiki.

 This vulnerability is associa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34095</guid>
    <pubDate>Mon, 11 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34095</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki.   This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php.    This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-34094 – Vulnerability in Wikimedia Foundation MediaWiki.

 This vulnerability is associa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34094</guid>
    <pubDate>Mon, 11 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-34094</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki.   This vulnerability is associated with program files includes/Page/Article.Php.    This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34093 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34093</guid>
    <pubDate>Mon, 11 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34093</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.   This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php.    This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34092 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34092</guid>
    <pubDate>Mon, 11 May 2026 16:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34092</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.   This vulnerability is associated with program files includes/Skin/Skin.Php.    This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34091 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34091</guid>
    <pubDate>Mon, 11 May 2026 16:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34091</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.  This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34088 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34088</guid>
    <pubDate>Mon, 11 May 2026 16:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34088</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.  This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10354 – Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10354</guid>
    <pubDate>Tue, 21 Apr 2026 15:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10354</strong></p>
  <p>Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the use…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39936 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39936</guid>
    <pubDate>Tue, 07 Apr 2026 23:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39936</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39935 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39935</guid>
    <pubDate>Tue, 07 Apr 2026 23:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39935</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39937 – Improper removal of sensitive information before storage or transfer vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39937</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39937</strong></p>
  <p>Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39934 – Loop with unreachable exit condition ('infinite loop') vulnerability in The Wiki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39934</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39934</strong></p>
  <p>Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue was remediated only on the `master` branch.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39933 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39933</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39933</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39841 – Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39841</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39841</strong></p>
  <p>Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39840 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39840</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39840</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extension: before 3.8.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39839 – Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39839</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39839</strong></p>
  <p>Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39838 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39838</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39838</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage Extension allows XSS Targeting Non-Script Elements. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39837 – Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39837</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39837</strong></p>
  <p>Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5762 – Allocation of resources without limits or throttling vulnerability in Wikimedia ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5762</guid>
    <pubDate>Tue, 07 Apr 2026 19:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5762</strong></p>
  <p>Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22711 – Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22711</guid>
    <pubDate>Tue, 07 Apr 2026 19:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22711</strong></p>
  <p>Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-87</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-30977 – RenderBlocking is a MediaWiki extension that allows interface administrators to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30977</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-30977</strong></p>
  <p>RenderBlocking is a MediaWiki extension that allows interface administrators to specify render-blocking CSS and JavaScript. Prior to 0.1.1, there is Stored XSS in renderblocking-css with Inline Assets mode. $wgRenderBlockingInlineAssets = true and editsitecss user rights are required. This vulnerability is fixed in 0.1.1.</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30917 – Bucket is a MediaWiki extension to store and retrieve structured data on article...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30917</guid>
    <pubDate>Tue, 10 Mar 2026 17:40:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30917</strong></p>
  <p>Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This vulnerability is fixed in 2.1.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24732 – Files or Directories Accessible to External Parties, Incorrect Permission Assign...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24732</guid>
    <pubDate>Wed, 04 Mar 2026 13:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24732</strong></p>
  <p>Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained by ACLs, Bypassing Electronic Locks and Access Controls.This issue affects BlueSpice: from 5.1 through 5.1.3, from 5.2 through 5.2.0.  HINT: Versions provided ap…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67484 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67484</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67484</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php.  This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67483 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67483</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67483</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Page.Preview.Js.  This issue affects MediaWiki: from * before 1.43.6, 1.44.3, 1.45.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67481 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67481</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67481</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.JqueryMsg/mediawiki.JqueryMsg.Js.  This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67480 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67480</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67480</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php.  This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-67479 – Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Cite. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67479</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-67479</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Cite. This vulnerability is associated with program files includes/Parser/CoreParserFunctions.Php, includes/Parser/Sanitizer.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Cite: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67477 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67477</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67477</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js.  This issue affects MediaWiki: from * before 1.44.3, 1.45.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67476 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67476</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67476</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php.  This issue affects MediaWiki: from * before 1.44.3, 1.45.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67475 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67475</guid>
    <pubDate>Tue, 03 Feb 2026 02:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67475</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/CommentFormatter/CommentParser.Php.  This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61646 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61646</guid>
    <pubDate>Tue, 03 Feb 2026 01:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61646</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61645 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61645</guid>
    <pubDate>Tue, 03 Feb 2026 01:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61645</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/pager/CodexTablePager.Php.  This issue affects MediaWiki: from * before 1.44.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11261 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11261</guid>
    <pubDate>Tue, 03 Feb 2026 01:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11261</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Language/mediawiki.Language.Js.  This issue affects MediaWiki: from * before 1.39.15, 1.43.5, 1.44.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-61644 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61644</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-61644</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/WatchlistTopSectionWidget.Js.  This issue affects MediaWiki: from * before > fb856ce9cf121e046305116852cca4899ecb48ca.</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61643 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61643</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61643</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61642 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61642</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61642</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61641 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61641</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61641</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61640 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61640</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61640</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/RclToOrFromWidget.Js.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61639 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61639</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61639</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/ManualLogEntry.Php, includes/recentchanges/RecentChangeFactory.Php, includes/recentchanges/RecentChangeStore.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61638 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61638</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61638</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoid: from * before 0.16.6, 0.20.4, 0.21.1.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61637 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61637</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61637</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Action/mediawiki.Action.Edit.Preview.Js, resources/src/mediawiki.Page.Preview.Js.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61636 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61636</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61636</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLButtonField.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-61634 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61634</guid>
    <pubDate>Tue, 03 Feb 2026 00:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-61634</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php.  This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-6927 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6927</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-6927</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/specials/pagers/BlockListPager.Php, includes/api/ApiQueryBlocks.Php.  This issue affects MediaWiki: from >= 1.42.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-6597 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6597</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-6597</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/auth/AuthManager.Php.  This issue affects MediaWiki: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6594 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6594</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6594</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandbox.Js.  This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-6593 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6593</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-6593</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/user/User.Php.  This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-6591 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6591</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-6591</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiFeedContributions.Php.  This issue affects MediaWiki: from * before 1.39.13, 1.42.7 1.43.2, 1.44.0.</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6590 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6590</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6590</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLUserTextField.Php.  This issue affects MediaWiki: from * through 1.39.12, 1.42.76 1.43.1, 1.44.0.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-6589 – Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6589</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-6589</strong></p>
  <p>Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/specials/pagers/BlockListPager.Php.  This issue affects MediaWiki: >= 1.42.0.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11175 – Improper Neutralization of Special Elements used in an Expression Language State...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11175</guid>
    <pubDate>Fri, 30 Jan 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11175</strong></p>
  <p>Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Blowup.This issue affects Mediawiki - DiscussionTools Extension: 1.44, 1.43.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0817 – Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - Campaign...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0817</guid>
    <pubDate>Fri, 09 Jan 2026 16:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0817</strong></p>
  <p>Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-22714 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22714</guid>
    <pubDate>Fri, 09 Jan 2026 00:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-22714</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Monaco Skin allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Monaco Skin: 1.45, 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22713 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22713</guid>
    <pubDate>Fri, 09 Jan 2026 00:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22713</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GrowthExperiments Extension: 1.45, 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22712 – Improper Encoding or Escaping of Output due to magic word replacement in ParserA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22712</guid>
    <pubDate>Fri, 09 Jan 2026 00:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22712</strong></p>
  <p>Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22710 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22710</guid>
    <pubDate>Fri, 09 Jan 2026 00:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22710</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Extension: 1.45, 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0671 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0671</guid>
    <pubDate>Thu, 08 Jan 2026 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0671</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0670 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0670</guid>
    <pubDate>Wed, 07 Jan 2026 19:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0670</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage Extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - ProofreadPage Extension: 1.45, 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0669 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0669</guid>
    <pubDate>Wed, 07 Jan 2026 18:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0669</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows Path Traversal.This issue affects MediaWiki - CSS extension: 1.44, 1.43, 1.39.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0668 – Inefficient Regular Expression Complexity vulnerability in Wikimedia Foundation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0668</guid>
    <pubDate>Wed, 07 Jan 2026 18:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0668</strong></p>
  <p>Inefficient Regular Expression Complexity vulnerability in Wikimedia Foundation MediaWiki - VisualData Extension allows Regular Expression Exponential Blowup.This issue affects MediaWiki - VisualData Extension: 1.45.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-67646 – TableProgressTracking is a MediaWiki extension to track progress against specifi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67646</guid>
    <pubDate>Thu, 11 Dec 2025 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-67646</strong></p>
  <p>TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would trigger unintended authenticated actions through the victim's browser. Due to the…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-62659 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62659</guid>
    <pubDate>Wed, 22 Oct 2025 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-62659</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki CookieConsent extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki CookieConsent extension: from v0.1.0 before v2.0.0.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62661 – Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawik...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62661</guid>
    <pubDate>Tue, 21 Oct 2025 20:20:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62661</strong></p>
  <p>Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension: from 1.43 before 1.44.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12004 – Incorrect Permission Assignment for Critical Resource vulnerability in The Wikim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12004</guid>
    <pubDate>Tue, 21 Oct 2025 07:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12004</strong></p>
  <p>Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: from master before 1.42.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62702 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62702</guid>
    <pubDate>Tue, 21 Oct 2025 05:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62702</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - PageTriage Extension allows Stored XSS.This issue affects Mediawiki - PageTriage Extension: from master before 1.44.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62701 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62701</guid>
    <pubDate>Tue, 21 Oct 2025 05:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62701</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikistories allows Stored XSS.This issue affects Mediawiki - Wikistories: from master before 1.44.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62694 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62694</guid>
    <pubDate>Tue, 21 Oct 2025 05:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62694</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLove Extension allows Stored XSS.This issue affects Mediawiki - WikiLove Extension: 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62699 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62699</guid>
    <pubDate>Tue, 21 Oct 2025 04:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62699</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Translate Extension allows Footprinting. Translate extension appears to use jobs to make edits to translation pages. This causes the CheckUser tool to log the wrong IP and User-Agent making these edits un-auditable via the CheckUser tool.This issue affects Mediawiki - Translate Extensi…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62696 – Improper Neutralization of Special Elements used in a Command ('Command Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62696</guid>
    <pubDate>Tue, 21 Oct 2025 04:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62696</strong></p>
  <p>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62695 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62695</guid>
    <pubDate>Tue, 21 Oct 2025 04:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62695</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Stored XSS.This issue affects Mediawiki - WikiLambda Extension: master.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62658 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62658</guid>
    <pubDate>Mon, 20 Oct 2025 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62658</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalytics extension allows SQL Injection.This issue affects MediaWiki WatchAnalytics extension: 1.43, 1.44.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62657 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62657</guid>
    <pubDate>Mon, 20 Oct 2025 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62657</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PageForms extension allows Stored XSS.This issue affects MediaWiki PageForms extension: 1.44.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62656 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62656</guid>
    <pubDate>Mon, 20 Oct 2025 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62656</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki GlobalBlocking extension allows Stored XSS.This issue affects MediaWiki GlobalBlocking extension: 1.43, 1.44.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62697 – Improper Neutralization of Special Elements in Output Used by a Downstream Compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62697</guid>
    <pubDate>Mon, 20 Oct 2025 20:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62697</strong></p>
  <p>Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62700 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62700</guid>
    <pubDate>Mon, 20 Oct 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62700</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - MultiBoilerplate Extensionmaste allows Stored XSS.This issue affects Mediawiki - MultiBoilerplate Extensionmaste: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62698 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62698</guid>
    <pubDate>Mon, 20 Oct 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62698</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ExternalGuidance allows Stored XSS.This issue affects Mediawiki - ExternalGuidance: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62693 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62693</guid>
    <pubDate>Mon, 20 Oct 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62693</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - LastModified Extension allows Stored XSS.This issue affects Mediawiki - LastModified Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11937 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11937</guid>
    <pubDate>Sat, 18 Oct 2025 06:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11937</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - SecurePoll Extension allows Stored XSS.This issue affects Mediawiki - SecurePoll Extension: master.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62671 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62671</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62671</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: master.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62670 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62670</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62670</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - FlexDiagrams Extension allows Stored XSS.This issue affects Mediawiki - FlexDiagrams Extension: master.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62669 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62669</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62669</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects Mediawiki - CentralAuth Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62668 – Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawik...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62668</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62668</strong></p>
  <p>Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62667 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62667</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62667</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Stored XSS.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62666 – Allocation of Resources Without Limits or Throttling vulnerability in The Wikime...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62666</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62666</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch Extension allows HTTP DoS.This issue affects Mediawiki - CirrusSearch Extension: from master before 1.43.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62664 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62664</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62664</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ImageRating Extension allows Stored XSS.This issue affects Mediawiki - ImageRating Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62663 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62663</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62663</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - UploadWizard Extension allows Stored XSS.This issue affects Mediawiki - UploadWizard Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62662 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62662</guid>
    <pubDate>Sat, 18 Oct 2025 05:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62662</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - AdvancedSearch Extension allows Stored XSS.This issue affects Mediawiki - AdvancedSearch Extension: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62665 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62665</guid>
    <pubDate>Sat, 18 Oct 2025 04:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62665</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Skin:BlueSky allows Stored XSS.This issue affects Mediawiki - Skin:BlueSky: from master before 1.39.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-62655 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62655</guid>
    <pubDate>Fri, 17 Oct 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-62655</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects MediaWiki Cargo extension: 1.39, 1.43, 1.44.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-62654 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62654</guid>
    <pubDate>Fri, 17 Oct 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-62654</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki QuizGame extension allows Stored XSS.This issue affects MediaWiki QuizGame extension: 1.39, 1.43, 1.44.</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-62653 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62653</guid>
    <pubDate>Fri, 17 Oct 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-62653</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PollNY extension allows Stored XSS.This issue affects MediaWiki PollNY extension: 1.39, 1.43, 1.44.</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62652 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62652</guid>
    <pubDate>Fri, 17 Oct 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62652</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62508 – Citizen is a MediaWiki skin that makes extensions part of the cohesive experienc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62508</guid>
    <pubDate>Fri, 17 Oct 2025 21:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62508</strong></p>
  <p>Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in the sticky header button message handling. In stickyHeader.js the copyButtonAttributes function assigns innerHTML from a source element’s textContent when copying button labels. This causes escaped HTML in system message content (such as c…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61766 – Bucket is a MediaWiki extension to store and retrieve structured data on article...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61766</guid>
    <pubDate>Mon, 06 Oct 2025 17:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61766</strong></p>
  <p>Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recursion can occur if a user queries a bucket using the `!=` comparator. This will result in PHP's call stack limit exceeding, and/or increased memory consumption, potentially leading to a denial of service. Version 1.0.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59839 – The EmbedVideo Extension is a MediaWiki extension which adds a parser function c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59839</guid>
    <pubDate>Thu, 25 Sep 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59839</strong></p>
  <p>The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59332 – 3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the &lt;3d&gt;...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59332</guid>
    <pubDate>Mon, 15 Sep 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59332</strong></p>
  <p>3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54865 – Tilesheets MediaWiki Extension adds a table lookup parser function for an item a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54865</guid>
    <pubDate>Tue, 05 Aug 2025 01:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54865</strong></p>
  <p>Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53625 – The DynamicPageList3 extension is a reporting tool for MediaWiki, listing catego...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53625</guid>
    <pubDate>Thu, 10 Jul 2025 19:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53625</strong></p>
  <p>The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revision deletion, suppression, or the hideuser block flag. The vulnerability is fixed in 3.6.4.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53371 – DiscordNotifications is an extension for MediaWiki that sends notifications of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53371</guid>
    <pubDate>Thu, 10 Jul 2025 18:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53371</strong></p>
  <p>DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows sending requests via curl and file_get_contents to arbitrary URLs set via $wgDiscordIncomingWebhookUrl and $wgDiscordAdditionalIncomingWebhookUrls. This allows for DOS by causing the server to read large files. SSRF is also possible if there are int…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7363 – The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7363</guid>
    <pubDate>Tue, 08 Jul 2025 18:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7363</strong></p>
  <p>The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript.     This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X befo…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7363">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
