mediawiki has 11 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (6). Most affected products: mediawiki/semantic-media-wiki (6), CheckUser (1), ProofreadPage (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 10 prev 1
Products
- mediawiki/semantic-media-wiki 6
- CheckUser 1
- ProofreadPage 1
- cargo 1
- mediawiki 1
- mediawiki/maps 1
Worst active — by depth score
CVE-2025-61682High· 8.6Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages59CVE-2026-52854High· 8.6Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps47CVE-2026-13707High· 7.6Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.42GHSA-jr78-w6w5-m8f8High· 7.3Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks40GHSA-9rcc-pmj8-ffhrMedium· 6.1Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)34
mediawiki vulnerabilities
CVEs affecting mediawiki, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
GHSA-jr78-w6w5-m8f8High· 7.3Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
GHSA-9rcc-pmj8-ffhrMedium· 6.1Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
CVE-2026-77616Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…
CVE-2026-77609Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…
CVE-2026-77606Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. U…
CVE-2025-61682High· 8.6PoCSemantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…
CVE-2023-37252Low· 3.1PoCAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
CVE-2023-37253Low· 3.1PoCAn issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3
An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.
CVE-2026-52854High· 8.6Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays p…
CVE-2026-13707High· 7.6Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
CVE-2026-39840Medium· 6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extensio…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extensio…