Mediawiki
437 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Mediawiki, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Mediawiki CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 7 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 29 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 7 |
| 2026-06 | 0 |
| 2026-07 | 22 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 437 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical21
- High79
- Medium306
- Low14
Latest CVEs
The 15 most recently published vulnerabilities affecting Mediawiki.
- CVE-2026-14358Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title6.1
- CVE-2026-58517Blocked users can create and edit WikiLambda objects4.3
- CVE-2026-58520UrlShortener defaults to ineffective validation open to third-party redirects6.1
- CVE-2026-58025Remote Code Execution via Unsafe Deserialization in LogItem Import9.8
- CVE-2026-58029Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata6.5
- CVE-2026-58028Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets5.4
- CVE-2026-58026$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces5.7
- CVE-2026-8857Full RCE using EasyTimeline Extension8.8
- CVE-2026-58038Stored XSS through javascript URLs in SVGs generated by EasyTimeline6.1
- CVE-2026-58027QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI6.5
- CVE-2026-58030SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute6.1
- CVE-2026-58032mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html6.1
- CVE-2026-58033"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted6.5
- CVE-2026-58037Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input6.1
- CVE-2026-58036Users API leaks whether privileged users have their user groups disabled for lack of 2FA7.5
Product grouping is registry-driven, with AI assist and human review. How it works