SomeRandomDeveloper
53 credited records · 43 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
0Monitor | CVE-2026-100238No exploit | Flow colon-separator and flow-guidedtour-optin-welcome-description messages allow stored XSSwikimedia foundation · mediawiki - flow extension · CWE-79 | — | — | — | Today |
19Monitor | CVE-2026-100383No exploit | Stored i18n XSS in WikiLambda's VisualEditor integrationwikimedia foundation · mediawiki - wikilambda extension · CWE-79 | Medium4.8 | — | 0.3% | 4 days ago |
40Plan | CVE-2026-100382Proof of concept | Unauthenticated remote code execution through wikitext in ExternalDatawikimedia foundation · mediawiki - externaldata extension · CWE-78 | Critical10.0 | — | 0.9% | 4 days ago |
27Monitor | CVE-2026-100377No exploit | Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstractwikimedia foundation · mediawiki - wikilambda extension · CWE-200 | Medium6.9 | — | 0.3% | 4 days ago |
24Monitor | CVE-2026-100237No exploit | Stored i18n XSS in the Flow integration of Thanksthe wikimedia foundation · mediawiki - thanks extension · CWE-79 | Medium6.1 | — | 0.2% | 4 days ago |
27Monitor | CVE-2026-58517No exploit | Blocked users can create and edit WikiLambda objectsmediawiki · mediawiki · CWE-288 | Medium6.9 | — | 0.3% | Jul 1, 2026 |
27Monitor | CVE-2026-58519No exploit | Stored XSS through Cargo's map formatmediawiki · cargo · CWE-79 | Medium6.9 | — | 0.2% | Jul 1, 2026 |
27Monitor | CVE-2026-58518No exploit | Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request mediawiki · mediawiki · CWE-352 | Medium6.9 | — | 0.1% | Jul 1, 2026 |
27Monitor | CVE-2026-39936No exploit | Stored XSS in Score due to usage of non-reserved data attributesthe wikimedia foundation · mediawiki - score extension · CWE-79 | Medium6.9 | — | 0.5% | Apr 7, 2026 |
27Monitor | CVE-2026-39933No exploit | Multiple XSS vulnerabilities in GlobalWatchlistthe wikimedia foundation · mediawiki - globalwatchlist extension · CWE-79 | Medium6.9 | — | 0.5% | Apr 7, 2026 |
20Monitor | CVE-2026-39840No exploit | CSS injection in multiple Cargo display formatsmediawiki · cargo · CWE-79 | Medium5.1 | — | 0.2% | Apr 7, 2026 |
25Monitor | CVE-2026-39839No exploit | Stored XSS through URLs in Cargo's map formatmediawiki · cargo · CWE-80 | Medium6.3 | — | 0.3% | Apr 7, 2026 |
27Monitor | CVE-2026-39838No exploit | ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSSwikimedia foundation · mediawiki - proofreadpage extension · CWE-79 | Medium6.9 | — | 0.5% | Apr 7, 2026 |
25Monitor | CVE-2026-39837No exploit | Stored XSS through the dynamic table format in Cargomediawiki · cargo · CWE-80 | Medium6.3 | — | 0.2% | Apr 7, 2026 |
27Monitor | CVE-2026-22711No exploit | Stored XSS through system messages in WikiLovethe wikimedia foundation · mediawiki - wikilove extension · CWE-87 | Medium6.9 | — | 0.3% | Apr 7, 2026 |
9Monitor | CVE-2026-22714No exploit | i18n XSS, DoS and config SQLI in Monacothe wikimedia foundation · mediawiki - monaco skin · CWE-79 | Low2.3 | — | 0.4% | Jan 8, 2026 |
9Monitor | CVE-2026-22713No exploit | Stored XSS through edit summaries in GrowthExperimentsgrowth · growthexperiments · CWE-79 | Low2.3 | — | 0.2% | Jan 8, 2026 |
9Monitor | CVE-2026-22712No exploit | ApprovedRevs allows bypassing the inline CSS sanitizerwikiworks · approved revs · CWE-116 | Low2.3 | — | 0.2% | Jan 8, 2026 |
9Monitor | CVE-2026-22710No exploit | Stored XSS through autocomment system messages in Wikibasewikimedia · wikibase · CWE-79 | Low2.3 | — | 0.2% | Jan 8, 2026 |
24Monitor | CVE-2026-0670No exploit | Stored XSS through a system message and a user-provided parameter in ProofreadPagewikisource · proofread page · CWE-79 | Medium6.1 | — | 0.2% | Jan 7, 2026 |
8Monitor | CVE-2025-62659No exploit | The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectorsthe wikimedia foundation · mediawiki cookieconsent extension · CWE-79 | Low2.1 | — | 0.3% | Oct 22, 2025 |
27Monitor | CVE-2025-62702No exploit | Stored XSS through system messagesthe wikimedia foundation · mediawiki - pagetriage extension · CWE-79 | Medium6.9 | — | 0.3% | Oct 21, 2025 |
27Monitor | CVE-2025-62701No exploit | Stored XSS through system messagesthe wikimedia foundation · mediawiki - wikistories · CWE-79 | Medium6.9 | — | 0.3% | Oct 21, 2025 |
27Monitor | CVE-2025-62694No exploit | Stored XSS through a system messagethe wikimedia foundation · mediawiki - wikilove extension · CWE-79 | Medium6.9 | — | 0.4% | Oct 21, 2025 |
27Monitor | CVE-2025-62695No exploit | Stored XSS through system messagesthe wikimedia foundation · mediawiki - wikilambda extension · CWE-79 | Medium6.9 | — | 0.3% | Oct 21, 2025 |
- CVE-2026-1002380Monitor
Flow colon-separator and flow-guidedtour-optin-welcome-description messages allow stored XSS
No exploitwikimedia foundation · mediawiki - flow extensionToday
- CVE-2026-10038319Monitor
Stored i18n XSS in WikiLambda's VisualEditor integration
MediumCVSS 4.8No exploitEPSS 0%wikimedia foundation · mediawiki - wikilambda extension4 days ago
- CVE-2026-10038240Plan
Unauthenticated remote code execution through wikitext in ExternalData
CriticalCVSS 10.0Proof of conceptEPSS 1%wikimedia foundation · mediawiki - externaldata extension4 days ago
- CVE-2026-10037727Monitor
Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstract
MediumCVSS 6.9No exploitEPSS 0%wikimedia foundation · mediawiki - wikilambda extension4 days ago
- CVE-2026-10023724Monitor
Stored i18n XSS in the Flow integration of Thanks
MediumCVSS 6.1No exploitEPSS 0%the wikimedia foundation · mediawiki - thanks extension4 days ago
- CVE-2026-5851727Monitor
Blocked users can create and edit WikiLambda objects
MediumCVSS 6.9No exploitEPSS 0%mediawiki · mediawikiJul 1, 2026
- CVE-2026-5851927Monitor
Stored XSS through Cargo's map format
MediumCVSS 6.9No exploitEPSS 0%mediawiki · cargoJul 1, 2026
- CVE-2026-5851827Monitor
Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request
MediumCVSS 6.9No exploitEPSS 0%mediawiki · mediawikiJul 1, 2026
- CVE-2026-3993627Monitor
Stored XSS in Score due to usage of non-reserved data attributes
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - score extensionApr 7, 2026
- CVE-2026-3993327Monitor
Multiple XSS vulnerabilities in GlobalWatchlist
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - globalwatchlist extensionApr 7, 2026
- CVE-2026-3984020Monitor
CSS injection in multiple Cargo display formats
MediumCVSS 5.1No exploitEPSS 0%mediawiki · cargoApr 7, 2026
- CVE-2026-3983925Monitor
Stored XSS through URLs in Cargo's map format
MediumCVSS 6.3No exploitEPSS 0%mediawiki · cargoApr 7, 2026
- CVE-2026-3983827Monitor
ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSS
MediumCVSS 6.9No exploitEPSS 0%wikimedia foundation · mediawiki - proofreadpage extensionApr 7, 2026
- CVE-2026-3983725Monitor
Stored XSS through the dynamic table format in Cargo
MediumCVSS 6.3No exploitEPSS 0%mediawiki · cargoApr 7, 2026
- CVE-2026-2271127Monitor
Stored XSS through system messages in WikiLove
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - wikilove extensionApr 7, 2026
- CVE-2026-227149Monitor
i18n XSS, DoS and config SQLI in Monaco
LowCVSS 2.3No exploitEPSS 0%the wikimedia foundation · mediawiki - monaco skinJan 8, 2026
- CVE-2026-227139Monitor
Stored XSS through edit summaries in GrowthExperiments
LowCVSS 2.3No exploitEPSS 0%growth · growthexperimentsJan 8, 2026
- CVE-2026-227129Monitor
ApprovedRevs allows bypassing the inline CSS sanitizer
LowCVSS 2.3No exploitEPSS 0%wikiworks · approved revsJan 8, 2026
- CVE-2026-227109Monitor
Stored XSS through autocomment system messages in Wikibase
LowCVSS 2.3No exploitEPSS 0%wikimedia · wikibaseJan 8, 2026
- CVE-2026-067024Monitor
Stored XSS through a system message and a user-provided parameter in ProofreadPage
MediumCVSS 6.1No exploitEPSS 0%wikisource · proofread pageJan 7, 2026
- CVE-2025-626598Monitor
The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors
LowCVSS 2.1No exploitEPSS 0%the wikimedia foundation · mediawiki cookieconsent extensionOct 22, 2025
- CVE-2025-6270227Monitor
Stored XSS through system messages
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - pagetriage extensionOct 21, 2025
- CVE-2025-6270127Monitor
Stored XSS through system messages
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - wikistoriesOct 21, 2025
- CVE-2025-6269427Monitor
Stored XSS through a system message
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - wikilove extensionOct 21, 2025
- CVE-2025-6269527Monitor
Stored XSS through system messages
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - wikilambda extensionOct 21, 2025