Wikimedia-foundation
125 CVEs tracked since 2025. Since Jan 2025, none of them reached CISA KEV.
Wikimedia-foundation CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-01 | 7 | 0 |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | 6 | 0 |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | 30 | 0 |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | 47 | 0 |
| 2026-03 | null or fewer | |
| 2026-04 | 6 | 0 |
| 2026-05 | 11 | 0 |
| 2026-06 | null or fewer | |
| 2026-07 | 18 | 0 |
Products
The products that kept showing up in Wikimedia-foundation's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Wikimedia-foundation.
- CVE-2026-100383Stored i18n XSS in WikiLambda's VisualEditor integration—
- CVE-2026-100382Unauthenticated remote code execution through wikitext in ExternalData—
- CVE-2026-100381UploadWizard Flickr collection and set titles allow DOM XSS—
- CVE-2026-100380Reflected XSS in Wikibase Special:SetLabel language validation—
- CVE-2026-100379Cross-request disclosure of CentralAuth cookies in Wikipedia Android App—
- CVE-2026-100378Missing permission check in the Translate sandbox doRemind action—
- CVE-2026-100376TemplateSandbox can be abused for XSS by asking another user to preview a page with a certain sandbox prefix—
- CVE-2026-100377Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstract—
- CVE-2026-58025Remote Code Execution via Unsafe Deserialization in LogItem Import9.8
- CVE-2026-58029Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata6.5
- CVE-2026-58028Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets5.4
- CVE-2026-58026$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces5.7
- CVE-2026-8857Full RCE using EasyTimeline Extension8.8
- CVE-2026-58038Stored XSS through javascript URLs in SVGs generated by EasyTimeline6.1
- CVE-2026-58027QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI6.5
The record
- Peak rank
- #16 in Feb 2026
- Busiest month shown
- Feb 2026, 47 CVEs
- Months with a KEV entry
- 0 since Jan 2025
- Monthly snapshots
- 7 since 2025