Exposição de MediaWiki

Wikis
45
score de exposição
21.763
sites usam
0
em exploração
0
críticos
Análise Vexday

Com 64 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o MediaWiki apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças práticas. A ausência de vulnerabilidades de severidade crítica reforça um perfil de risco moderado, embora a presença de 6 CVEs surgidas nos últimos 90 dias indique atividade contínua de descoberta que merece acompanhamento. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente associado a riscos de injeção de conteúdo e sequestro de sessão em aplicações web colaborativas. A CVE mais perigosa em destaque, CVE-2012-4381, apresenta EPSS de aproximadamente 0,04, valor baixo que, combinado com a ausência de registros KEV, sugere exploração improvável no curto prazo — ainda assim, vulnerabilidades antigas sem correção aplicada merecem verificação em ambientes legados.

CVEs

75 resultados
CVE-2025-32696NONE"reupload-own" restriction can be bypassed by reverting fileEPSS 0.4%CVE-2026-58029MEDIUMFull Account Takeover from BotPasswords and OAuth via action=changeauthenticationdataEPSS 0.4%CVE-2025-6594NONEXSS in Special:ApiSandboxEPSS 0.3%CVE-2026-58036LOWUsers API leaks whether privileged users have their user groups disabled for lack of 2FAEPSS 0.3%CVE-2026-58032MEDIUMmw.Api.getErrorMessage() may return injected HTML if used without errorformat=htmlEPSS 0.3%CVE-2026-34091MEDIUMUser localization leaked by AbuseFilter + EventStreamEPSS 0.3%CVE-2026-34088LOWRecentChanges entries expose suppressed content via generated log page htmlEPSS 0.3%CVE-2025-61634NONEHTML rest endpoint needs PoolCounter and proper parser cache checkEPSS 0.3%CVE-2025-61641LOWAPI list=allpages with maxsize is making really slow queriesEPSS 0.3%CVE-2026-58035NONEStored XSS through a system message in the codex version of Special:BlockEPSS 0.3%CVE-2025-67479NONEMagic word replacement in legacy parser allows using reserved data attributes through wikitextEPSS 0.3%CVE-2026-58037NONECore log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled inputEPSS 0.3%CVE-2025-67476LOWImporting leaks IP address of importer via EventStreamsEPSS 0.3%CVE-2026-58031NONEStored i18n XSS in Special:ApiSandbox when a deprecated module is selectedEPSS 0.3%CVE-2026-58028NONEPretty-printed API output combined with centralauthtoken allows XSS with certain gadgetsEPSS 0.3%CVE-2025-61644NONEi18n XSS through Special:WatchlistEPSS 0.3%CVE-2025-61638NONESanitizer::validateAttributes data-XSSEPSS 0.2%CVE-2025-61643LOWEventStreams publishes suppressed recent change entries that are suppressed from their creationEPSS 0.2%CVE-2025-61646LOWWatchlist group mode reveals authors of edits with hidden authorshipEPSS 0.2%CVE-2026-34092LOWBlock UI elements in 'tools'-sidebar shows presence of an autoblocked IPEPSS 0.2%