Vulnerabilities in Wikimedia Foundation

136 results
Vexday analysis

Com 118 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco da Wikimedia Foundation situa-se abaixo da média geral do catálogo, o que sugere baixa pressão de ameaças imediatas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web de grande escala e que requer atenção contínua em processos de sanitização de entrada. As 3 CVEs de severidade crítica e as 17 surgidas nos últimos 90 dias indicam uma superfície em expansão moderada que merece acompanhamento. A CVE mais perigosa atualmente apontada é CVE-2013-4572, com escore EPSS de 0,0214, valor baixo que, somado à ausência de PoCs públicas conhecidas, não sinaliza risco de exploração elevado no curto prazo, mas a antiguidade da vulnerabilidade pode indicar débito técnico pendente de correção.

CVE-2026-58035NONEStored XSS through a system message in the codex version of Special:BlockEPSS 0.3%CVE-2025-67479NONEMagic word replacement in legacy parser allows using reserved data attributes through wikitextEPSS 0.3%CVE-2026-58034NONEStored XSS through a system message when blocking a temporary account that's related to other temporary accountsEPSS 0.3%CVE-2026-34090MEDIUMSuggested investigations: Handle suppressed usernamesEPSS 0.3%CVE-2026-0817MEDIUMCampaignEvents API missing authorization exposes meeting and chat URLsEPSS 0.3%CVE-2025-67476LOWImporting leaks IP address of importer via EventStreamsEPSS 0.3%CVE-2026-58038NONEStored XSS through javascript URLs in SVGs generated by EasyTimelineEPSS 0.3%CVE-2026-58037NONECore log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled inputEPSS 0.3%CVE-2026-58030MEDIUMSyntaxHighlight stored XSS via unsanitized 'linelinks' attributeEPSS 0.3%CVE-2025-61652LOWAction API discussiontoolspageinfo does not check for authorizeRead for the pageEPSS 0.3%CVE-2026-58028NONEPretty-printed API output combined with centralauthtoken allows XSS with certain gadgetsEPSS 0.3%CVE-2026-34087MEDIUMUsers API leaks whether privileged users have their user groups disabled for lack of 2FAEPSS 0.3%CVE-2026-58031NONEStored i18n XSS in Special:ApiSandbox when a deprecated module is selectedEPSS 0.3%CVE-2025-61644NONEi18n XSS through Special:WatchlistEPSS 0.3%CVE-2025-61650LOWUserInfoCard is vulnerable to message key stored XSSEPSS 0.3%CVE-2025-61657NONEImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Vector. ThEPSS 0.3%CVE-2026-5762MEDIUMReportIncident DiscussionTools integration causes slow requestsEPSS 0.3%CVE-2025-23078MEDIUMXSS in BreadCrumbs2EPSS 0.3%CVE-2025-53492LOWStored XSS in MintyDocsEPSS 0.3%CVE-2025-53485HIGHSecurePoll: Unauthorized access to SetTranslationHandler allows arbitrary text changesEPSS 0.3%