CVE Tools

Wikimedia-foundation

125 CVEs tracked since 2025. Since Jan 2025, none of them reached CISA KEV.

Wikimedia-foundation CVEs per month

Jan 2025 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Wikimedia-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0170
2025-02null or fewer
2025-03null or fewer
2025-0460
2025-05null or fewer
2025-06null or fewer
2025-07300
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02470
2026-03null or fewer
2026-0460
2026-05110
2026-06null or fewer
2026-07180

Products

The products that kept showing up in Wikimedia-foundation's monthly top three, with their CVEs summed over those months.

  1. Mediawiki514 months
  2. Checkuser82 months
  3. Mediawiki - Cargo Extension41 month
  4. Mediawiki - Abusefilter Extension31 month
  5. Mediawiki - Checkuser Extension31 month
  6. Mediawiki - Securepoll Extension31 month
  7. Timeline21 month
  8. Visualeditor21 month
  9. Echo11 month
  10. Mediawiki - Articlefeedbackv5 Extension11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wikimedia-foundation.

  1. CVE-2026-100383Stored i18n XSS in WikiLambda's VisualEditor integration—
  2. CVE-2026-100382Unauthenticated remote code execution through wikitext in ExternalData—
  3. CVE-2026-100381UploadWizard Flickr collection and set titles allow DOM XSS—
  4. CVE-2026-100380Reflected XSS in Wikibase Special:SetLabel language validation—
  5. CVE-2026-100379Cross-request disclosure of CentralAuth cookies in Wikipedia Android App—
  6. CVE-2026-100378Missing permission check in the Translate sandbox doRemind action—
  7. CVE-2026-100376TemplateSandbox can be abused for XSS by asking another user to preview a page with a certain sandbox prefix—
  8. CVE-2026-100377Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstract—
  9. CVE-2026-58025Remote Code Execution via Unsafe Deserialization in LogItem Import9.8
  10. CVE-2026-58029Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata6.5
  11. CVE-2026-58028Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets5.4
  12. CVE-2026-58026$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces5.7
  13. CVE-2026-8857Full RCE using EasyTimeline Extension8.8
  14. CVE-2026-58038Stored XSS through javascript URLs in SVGs generated by EasyTimeline6.1
  15. CVE-2026-58027QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI6.5

The record

Peak rank
#16 in Feb 2026
Busiest month shown
Feb 2026, 47 CVEs
Months with a KEV entry
0 since Jan 2025
Monthly snapshots
7 since 2025
Wikimedia-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store