The-wikimedia-foundation
64 CVEs tracked since 2024. Since Oct 2024, none of them reached CISA KEV.
The-wikimedia-foundation CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-10 | 7 | 0 |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | 14 | 0 |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | 30 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | 6 | 0 |
| 2026-05 | null or fewer | |
| 2026-06 | null or fewer | |
| 2026-07 | 7 | 0 |
Products
The products that kept showing up in The-wikimedia-foundation's monthly top three, with their CVEs summed over those months.
- Mediawiki - Cargo3
- Mediawiki - Cargo Extension3
- Mediawiki - Css Extension2
- Mediawiki - Growthexperiments Extension2
- Mediawiki - Ajax Poll Extension1
- Mediawiki - Apex Skin1
- Mediawiki - Campaignevents Extension1
- Mediawiki - Centralauth Extension1
- Mediawiki - Charts Extension1
- Mediawiki - Confirm Account Extension1
Latest CVEs
The 15 most recently published vulnerabilities affecting The-wikimedia-foundation.
- CVE-2026-96879"Checked by" label in page history should not be shown if the underlying review log entry is suppressed"—
- CVE-2026-96878Cargo Exhibit field alias allows stored XSS—
- CVE-2026-96877Reflected XSS through Cargo Drilldown full-text search—
- CVE-2026-96876Anonymous reflected XSS in CargoExport invalid-alias errors—
- CVE-2026-96875Reflected XSS in Cargo Drilldown hierarchy filters—
- CVE-2026-100237Stored i18n XSS in the Flow integration of Thanks6.1
- CVE-2026-96874Stored XSS in Cargo Drilldown tab names—
- CVE-2026-96873Reflected XSS in CirrusSearch debug explain output—
- CVE-2026-96872WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions—
- CVE-2026-14363Cargo Extension: SQLi in Special:Drilldown9.8
- CVE-2026-14358Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title6.1
- CVE-2026-58517Blocked users can create and edit WikiLambda objects4.3
- CVE-2026-58521SQLi in Cargo extension via year range filter9.8
- CVE-2026-58520UrlShortener defaults to ineffective validation open to third-party redirects6.1
- CVE-2026-58519Stored XSS through Cargo's map format5.4
The record
- Peak rank
- #38 in Oct 2025
- Busiest month shown
- Oct 2025, 30 CVEs
- Months with a KEV entry
- 0 since Oct 2024
- Monthly snapshots
- 5 since 2024