Skip to content
Noroxi

SomeRandomDeveloper

53 credited records · 43 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Flow colon-separator and flow-guidedtour-optin-welcome-description messages allow stored XSS

    No exploit

    wikimedia foundation · mediawiki - flow extensionToday

  • Stored i18n XSS in WikiLambda's VisualEditor integration

    MediumCVSS 4.8No exploitEPSS 0%

    wikimedia foundation · mediawiki - wikilambda extension4 days ago

  • Unauthenticated remote code execution through wikitext in ExternalData

    CriticalCVSS 10.0Proof of conceptEPSS 1%

    wikimedia foundation · mediawiki - externaldata extension4 days ago

  • Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstract

    MediumCVSS 6.9No exploitEPSS 0%

    wikimedia foundation · mediawiki - wikilambda extension4 days ago

  • Stored i18n XSS in the Flow integration of Thanks

    MediumCVSS 6.1No exploitEPSS 0%

    the wikimedia foundation · mediawiki - thanks extension4 days ago

  • Blocked users can create and edit WikiLambda objects

    MediumCVSS 6.9No exploitEPSS 0%

    mediawiki · mediawikiJul 1, 2026

  • Stored XSS through Cargo's map format

    MediumCVSS 6.9No exploitEPSS 0%

    mediawiki · cargoJul 1, 2026

  • Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request

    MediumCVSS 6.9No exploitEPSS 0%

    mediawiki · mediawikiJul 1, 2026

  • Stored XSS in Score due to usage of non-reserved data attributes

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - score extensionApr 7, 2026

  • Multiple XSS vulnerabilities in GlobalWatchlist

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - globalwatchlist extensionApr 7, 2026

  • CSS injection in multiple Cargo display formats

    MediumCVSS 5.1No exploitEPSS 0%

    mediawiki · cargoApr 7, 2026

  • Stored XSS through URLs in Cargo's map format

    MediumCVSS 6.3No exploitEPSS 0%

    mediawiki · cargoApr 7, 2026

  • ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSS

    MediumCVSS 6.9No exploitEPSS 0%

    wikimedia foundation · mediawiki - proofreadpage extensionApr 7, 2026

  • Stored XSS through the dynamic table format in Cargo

    MediumCVSS 6.3No exploitEPSS 0%

    mediawiki · cargoApr 7, 2026

  • Stored XSS through system messages in WikiLove

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - wikilove extensionApr 7, 2026

  • i18n XSS, DoS and config SQLI in Monaco

    LowCVSS 2.3No exploitEPSS 0%

    the wikimedia foundation · mediawiki - monaco skinJan 8, 2026

  • Stored XSS through edit summaries in GrowthExperiments

    LowCVSS 2.3No exploitEPSS 0%

    growth · growthexperimentsJan 8, 2026

  • ApprovedRevs allows bypassing the inline CSS sanitizer

    LowCVSS 2.3No exploitEPSS 0%

    wikiworks · approved revsJan 8, 2026

  • Stored XSS through autocomment system messages in Wikibase

    LowCVSS 2.3No exploitEPSS 0%

    wikimedia · wikibaseJan 8, 2026

  • CVE-2026-0670
    24Monitor

    Stored XSS through a system message and a user-provided parameter in ProofreadPage

    MediumCVSS 6.1No exploitEPSS 0%

    wikisource · proofread pageJan 7, 2026

  • The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors

    LowCVSS 2.1No exploitEPSS 0%

    the wikimedia foundation · mediawiki cookieconsent extensionOct 22, 2025

  • Stored XSS through system messages

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - pagetriage extensionOct 21, 2025

  • Stored XSS through system messages

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - wikistoriesOct 21, 2025

  • Stored XSS through a system message

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - wikilove extensionOct 21, 2025

  • Stored XSS through system messages

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - wikilambda extensionOct 21, 2025