Vulnerabilidades em The Wikimedia Foundation

69 resultados
Análise Vexday

Com 62 CVEs catalogadas e nenhuma registrada no catálogo CISA KEV, a Wikimedia Foundation apresenta taxa de exploração ativa abaixo da média geral, o que sugere um perfil de risco operacional relativamente contido até o momento. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), uma classe de vulnerabilidade que, embora comum, pode facilitar ataques de injeção de conteúdo em aplicações web de alto tráfego. A CVE mais preocupante no momento é CVE-2024-47841, que registra o maior EPSS do conjunto (0,3418), indicando probabilidade estatisticamente relevante de exploração futura e merecendo atenção prioritária nas equipes de correção. O surgimento de 6 novas CVEs nos últimos 90 dias recomenda monitoramento contínuo, especialmente dado o volume de usuários e a natureza pública da plataforma.

CVE-2024-47840MEDIUMStored XSS through sidebar in Apex skinEPSS 0.3%CVE-2026-58517MEDIUMBlocked users can create and edit WikiLambda objectsEPSS 0.3%CVE-2025-12004CRITICALThe compare API module breaks Extension:LockdownEPSS 0.3%CVE-2025-62653LOWStored XSS through system messages in PollNYEPSS 0.3%CVE-2025-62654LOWStored XSS through system messages in QuizGameEPSS 0.3%CVE-2026-14358MEDIUMStored XSS in Wikimedia Chart pie tooltip via Data:*.tab field titleEPSS 0.3%CVE-2026-22711MEDIUMStored XSS through system messages in WikiLoveEPSS 0.3%CVE-2025-62659LOWThe CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectorsEPSS 0.3%CVE-2026-39935MEDIUMXSS-via-i18n in localised wiki namesEPSS 0.3%CVE-2024-47846MEDIUMSpecial:DeleteCargoTable and Special:SwitchCargoTable have no CSRF protectionEPSS 0.3%CVE-2026-58520MEDIUMUrlShortener defaults to ineffective validation open to third-party redirectsEPSS 0.3%CVE-2025-62655LOWSQL injection in Cargo via Special:CargoExportEPSS 0.3%CVE-2025-32068MEDIUMRevoking authorization of OAuth2 consumer does not invalidate refresh tokensEPSS 0.3%CVE-2025-62657MEDIUMStored XSS through system messages in PageFormsEPSS 0.3%CVE-2025-62656MEDIUMGlobalBlocking Special:GlobalBlockList vulnerable to message key stored XSSEPSS 0.3%CVE-2026-39936MEDIUMStored XSS in Score due to usage of non-reserved data attributesEPSS 0.3%CVE-2026-39937HIGHGlobal vanishing does not completely remove user emailEPSS 0.3%CVE-2026-22712LOWApprovedRevs allows bypassing the inline CSS sanitizerEPSS 0.2%CVE-2025-62658HIGHSQL injection in WatchAnalytics through Special:ClearPendingReviewsEPSS 0.2%CVE-2026-58519MEDIUMStored XSS through Cargo's map formatEPSS 0.2%