Wikimedia records
15 published records for vendor wikimedia.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 46.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2024-47841No exploit | Path traversal when loading stylesheetswikimedia · wikimedia-extensions-css · CWE-22 | Medium6.9 | — | 34.6% | Oct 4, 2024 |
27Monitor | CVE-2024-47848No exploit | User can review/unreview articles while blockedthe wikimedia foundation · mediawiki - pagetriage · CWE-200 | Medium6.9 | — | 0.5% | Oct 4, 2024 |
27Monitor | CVE-2024-47845No exploit | CSS sanitizer used incorrectly, and is easily bypassedwikimedia · wikimedia-extensions-css · CWE-116 | Medium6.9 | — | 0.4% | Oct 4, 2024 |
27Monitor | CVE-2024-47840No exploit | Stored XSS through sidebar in Apex skinwikimedia · apex · CWE-79 | Medium6.9 | — | 0.3% | Oct 4, 2024 |
24Monitor | CVE-2019-19329No exploit | In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arwikimedia · wikidata query gui · CWE-79 | Medium6.1 | — | 1.4% | Nov 27, 2019 |
24Monitor | CVE-2021-30458No exploit | An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2.wikimedia · parsoid · CWE-79 | Medium6.1 | — | 1.0% | Apr 9, 2021 |
24Monitor | CVE-2019-19328No exploit | ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entitwikimedia · wikidata query gui · CWE-79 | Medium6.1 | — | 0.9% | Nov 27, 2019 |
24Monitor | CVE-2019-19327No exploit | ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of wikimedia · wikidata query gui · CWE-79 | Medium6.1 | — | 0.9% | Nov 27, 2019 |
24Monitor | CVE-2020-36324No exploit | Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json conwikimedia · analytics-quarry-web · CWE-79 | Medium6.1 | — | 0.6% | Apr 21, 2021 |
24Monitor | CVE-2018-25065No exploit | Wikimedia mediawiki-extensions-I18nTags Unlike Parser I18nTags_body.php cross site scriptingwikimedia · mediawiki-extensions-i18ntags · CWE-79 | Medium6.1 | — | 0.5% | Jan 5, 2023 |
24Monitor | CVE-2026-0671No exploit | Multiple stored i18n/message-key XSSes in UploadWizardwikimedia · mediawiki-extensions-uploadwizard · CWE-79 | Medium6.1 | — | 0.2% | Jan 8, 2026 |
21Monitor | CVE-2026-0817No exploit | CampaignEvents API missing authorization exposes meeting and chat URLswikimedia · campaignevents · CWE-862 | Medium5.3 | — | 0.3% | Jan 9, 2026 |
9Monitor | CVE-2026-34089No exploit | Memory leak in Scribunto causes runJobs.php to run out of memorywikimedia · scribunto · CWE-401 | Low2.3 | — | 0.4% | May 11, 2026 |
9Monitor | CVE-2026-22710No exploit | Stored XSS through autocomment system messages in Wikibasewikimedia · wikibase · CWE-79 | Low2.3 | — | 0.2% | Jan 8, 2026 |
0Monitor | CVE-2025-61638Proof of concept | Sanitizer::validateAttributes data-XSSmediawiki · mediawiki · CWE-79 | —0.0 | — | 0.2% | Feb 2, 2026 |
- CVE-2024-4784137Monitor
Path traversal when loading stylesheets
MediumCVSS 6.9No exploitEPSS 35%wikimedia · wikimedia-extensions-cssOct 4, 2024
- CVE-2024-4784827Monitor
User can review/unreview articles while blocked
MediumCVSS 6.9No exploitEPSS 1%the wikimedia foundation · mediawiki - pagetriageOct 4, 2024
- CVE-2024-4784527Monitor
CSS sanitizer used incorrectly, and is easily bypassed
MediumCVSS 6.9No exploitEPSS 0%wikimedia · wikimedia-extensions-cssOct 4, 2024
- CVE-2024-4784027Monitor
Stored XSS through sidebar in Apex skin
MediumCVSS 6.9No exploitEPSS 0%wikimedia · apexOct 4, 2024
- CVE-2019-1932924Monitor
In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, ar
MediumCVSS 6.1No exploitEPSS 1%wikimedia · wikidata query guiNov 27, 2019
- CVE-2021-3045824Monitor
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2.
MediumCVSS 6.1No exploitEPSS 1%wikimedia · parsoidApr 9, 2021
- CVE-2019-1932824Monitor
ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entit
MediumCVSS 6.1No exploitEPSS 1%wikimedia · wikidata query guiNov 27, 2019
- CVE-2019-1932724Monitor
ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of
MediumCVSS 6.1No exploitEPSS 1%wikimedia · wikidata query guiNov 27, 2019
- CVE-2020-3632424Monitor
Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json con
MediumCVSS 6.1No exploitEPSS 1%wikimedia · analytics-quarry-webApr 21, 2021
- CVE-2018-2506524Monitor
Wikimedia mediawiki-extensions-I18nTags Unlike Parser I18nTags_body.php cross site scripting
MediumCVSS 6.1No exploitEPSS 1%wikimedia · mediawiki-extensions-i18ntagsJan 5, 2023
- CVE-2026-067124Monitor
Multiple stored i18n/message-key XSSes in UploadWizard
MediumCVSS 6.1No exploitEPSS 0%wikimedia · mediawiki-extensions-uploadwizardJan 8, 2026
- CVE-2026-081721Monitor
CampaignEvents API missing authorization exposes meeting and chat URLs
MediumCVSS 5.3No exploitEPSS 0%wikimedia · campaigneventsJan 9, 2026
- CVE-2026-340899Monitor
Memory leak in Scribunto causes runJobs.php to run out of memory
LowCVSS 2.3No exploitEPSS 0%wikimedia · scribuntoMay 11, 2026
- CVE-2026-227109Monitor
Stored XSS through autocomment system messages in Wikibase
LowCVSS 2.3No exploitEPSS 0%wikimedia · wikibaseJan 8, 2026
- CVE-2025-616380Monitor
Sanitizer::validateAttributes data-XSS
CVSS 0.0Proof of conceptEPSS 0%mediawiki · mediawikiFeb 2, 2026