CVE Tools

The-wikimedia-foundation

64 CVEs tracked since 2024. Since Oct 2024, none of them reached CISA KEV.

The-wikimedia-foundation CVEs per month

Oct 2024 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
The-wikimedia-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-1070
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04140
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10300
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0460
2026-05null or fewer
2026-06null or fewer
2026-0770

Products

The products that kept showing up in The-wikimedia-foundation's monthly top three, with their CVEs summed over those months.

  1. Mediawiki - Cargo31 month
  2. Mediawiki - Cargo Extension31 month
  3. Mediawiki - Css Extension21 month
  4. Mediawiki - Growthexperiments Extension21 month
  5. Mediawiki - Ajax Poll Extension11 month
  6. Mediawiki - Apex Skin11 month
  7. Mediawiki - Campaignevents Extension11 month
  8. Mediawiki - Centralauth Extension11 month
  9. Mediawiki - Charts Extension11 month
  10. Mediawiki - Confirm Account Extension11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting The-wikimedia-foundation.

  1. CVE-2026-96879"Checked by" label in page history should not be shown if the underlying review log entry is suppressed"—
  2. CVE-2026-96878Cargo Exhibit field alias allows stored XSS—
  3. CVE-2026-96877Reflected XSS through Cargo Drilldown full-text search—
  4. CVE-2026-96876Anonymous reflected XSS in CargoExport invalid-alias errors—
  5. CVE-2026-96875Reflected XSS in Cargo Drilldown hierarchy filters—
  6. CVE-2026-100237Stored i18n XSS in the Flow integration of Thanks6.1
  7. CVE-2026-96874Stored XSS in Cargo Drilldown tab names—
  8. CVE-2026-96873Reflected XSS in CirrusSearch debug explain output—
  9. CVE-2026-96872WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions—
  10. CVE-2026-14363Cargo Extension: SQLi in Special:Drilldown9.8
  11. CVE-2026-14358Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title6.1
  12. CVE-2026-58517Blocked users can create and edit WikiLambda objects4.3
  13. CVE-2026-58521SQLi in Cargo extension via year range filter9.8
  14. CVE-2026-58520UrlShortener defaults to ineffective validation open to third-party redirects6.1
  15. CVE-2026-58519Stored XSS through Cargo's map format5.4

The record

Peak rank
#38 in Oct 2025
Busiest month shown
Oct 2025, 30 CVEs
Months with a KEV entry
0 since Oct 2024
Monthly snapshots
5 since 2024
The-wikimedia-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store