Vulnerabilidades em Wikimedia Foundation

136 resultados
Análise Vexday

Com 118 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco da Wikimedia Foundation situa-se abaixo da média geral do catálogo, o que sugere baixa pressão de ameaças imediatas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web de grande escala e que requer atenção contínua em processos de sanitização de entrada. As 3 CVEs de severidade crítica e as 17 surgidas nos últimos 90 dias indicam uma superfície em expansão moderada que merece acompanhamento. A CVE mais perigosa atualmente apontada é CVE-2013-4572, com escore EPSS de 0,0214, valor baixo que, somado à ausência de PoCs públicas conhecidas, não sinaliza risco de exploração elevado no curto prazo, mas a antiguidade da vulnerabilidade pode indicar débito técnico pendente de correção.

CVE-2025-32700LOWAbuseFilter log interfaces expose global private and hidden filters when central DB is not availableEPSS 0.4%CVE-2026-58033MEDIUM"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deletedEPSS 0.4%CVE-2025-6926HIGHSecurity Authentication Bypass in CentralAuthEPSS 0.4%CVE-2025-6596NONEVector inserts portlet labels as HTML, allowing for stored XSS through system messagesEPSS 0.4%CVE-2026-39838MEDIUMProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSSEPSS 0.4%CVE-2025-32699LOWPotential javascript injection attack enabled by Unicode normalization in Action APIEPSS 0.4%CVE-2025-32697NONECascading protection is not preventing file reversionsEPSS 0.4%CVE-2025-6590MEDIUMComplete content leak of private wikis due to PasswordReset Wikitext injection in error messageEPSS 0.4%CVE-2025-6592LOWCreating a permanent account from a temporary account associates temp username and IP address with real username in AbuseLogEPSS 0.4%CVE-2025-61635NONEAdd rate limiting to ApiFancyCaptchaReloadEPSS 0.4%CVE-2025-11173NONEReauth for enabling 2FA can be bypassed by submitting a formEPSS 0.4%CVE-2026-58027MEDIUMQueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UIEPSS 0.4%CVE-2026-58024MEDIUMAPI identification of users on private wikisEPSS 0.4%CVE-2026-58026NONE$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespacesEPSS 0.4%CVE-2025-32696NONE"reupload-own" restriction can be bypassed by reverting fileEPSS 0.4%CVE-2025-61653LOWExtension:TextExtracts does not check for authorizeRead when returning extractsEPSS 0.4%CVE-2026-58029MEDIUMFull Account Takeover from BotPasswords and OAuth via action=changeauthenticationdataEPSS 0.4%CVE-2025-23074LOWSpecial:EditProfile exposes the contents of profile fields marked "hidden"/friends or "friends of friends" when the privileged user isn't a friend of the user whose profile they edit(ed)EPSS 0.3%CVE-2026-34089LOWMemory leak in Scribunto causes runJobs.php to run out of memoryEPSS 0.3%CVE-2026-13707NONESession fixation attacks on improperly configured OAuth 1.0a toolsEPSS 0.3%