Exposure of MediaWiki
Wikis21
exposure score
21,763
sites use
0
exploited
0
critical
CVEs
75 resultsCVE-2025-6590MEDIUMComplete content leak of private wikis due to PasswordReset Wikitext injection in error messageEPSS 0.4%CVE-2026-58026NONE$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespacesEPSS 0.4%CVE-2025-32696NONE"reupload-own" restriction can be bypassed by reverting fileEPSS 0.4%CVE-2026-58029MEDIUMFull Account Takeover from BotPasswords and OAuth via action=changeauthenticationdataEPSS 0.4%CVE-2026-34092LOWBlock UI elements in 'tools'-sidebar shows presence of an autoblocked IPEPSS 0.3%CVE-2026-58036LOWUsers API leaks whether privileged users have their user groups disabled for lack of 2FAEPSS 0.3%CVE-2025-61634NONEHTML rest endpoint needs PoolCounter and proper parser cache checkEPSS 0.3%CVE-2025-61641LOWAPI list=allpages with maxsize is making really slow queriesEPSS 0.3%CVE-2025-6594NONEXSS in Special:ApiSandboxEPSS 0.3%CVE-2026-34093LOWSpecial:UserRights allows viewing user rights from private wikiEPSS 0.3%CVE-2025-67479NONEMagic word replacement in legacy parser allows using reserved data attributes through wikitextEPSS 0.3%CVE-2026-58032MEDIUMmw.Api.getErrorMessage() may return injected HTML if used without errorformat=htmlEPSS 0.3%CVE-2025-67476LOWImporting leaks IP address of importer via EventStreamsEPSS 0.3%CVE-2026-58035NONEStored XSS through a system message in the codex version of Special:BlockEPSS 0.3%CVE-2025-61644NONEi18n XSS through Special:WatchlistEPSS 0.3%CVE-2026-34095NONEaction=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript requestEPSS 0.3%CVE-2025-61646LOWWatchlist group mode reveals authors of edits with hidden authorshipEPSS 0.3%CVE-2025-61638NONESanitizer::validateAttributes data-XSSEPSS 0.3%CVE-2026-58037NONECore log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled inputEPSS 0.3%CVE-2026-58028NONEPretty-printed API output combined with centralauthtoken allows XSS with certain gadgetsEPSS 0.3%