CVE-2013-6455: vulnerability in Wikimedia Foundation MediaWiki
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.1%
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
nono source reports it
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.
Affected products
Wikimedia Foundation · MediaWikiRelated CVEs — Wikimedia Foundation MediaWiki
In the same product, most dangerous first.
CVE-2013-4572—CVE-2013-4572EPSS 2.1%CVE-2013-4303—CVE-2013-4303EPSS 1.5%CVE-2013-6451—CVE-2013-6451EPSS 1.1%CVE-2025-6597NONEMediaWiki should not consider autocreation as login for the purposes of security reauthenticationEPSS 0.5%CVE-2025-6927LOWAutoblocks from global account suppressions are publicly visibleEPSS 0.5%CVE-2026-58025MEDIUMRemote Code Execution via Unsafe Deserialization in LogItem ImportEPSS 0.5%