Mediawiki
Mediawiki Checkuser: vulnerabilidades y CVE
Mediawiki Checkuser tiene 12 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-37252 | Baja (3.1) | 0.24% | — | 14 sept 2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden. |
| CVE-2026-34090 | Media (4.8) | 0.38% | — | 11 may 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2. |
| CVE-2025-67478 | Ninguna (0) | 0.32% | — | 3 feb 2026 | Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php. This issue affects CheckUser: from * before 1.39.14, 1.43.4, 1.44.1. |
| CVE-2025-61658 | Baja (1.3) | 0.25% | — | 3 feb 2026 | Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/GlobalContributions/GlobalContributionsPager.Php. This issue affects CheckUser: from * before 1.43.4, 1.44.1. |
| CVE-2025-61651 | Ninguna (0) | 0.20% | — | 3 feb 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files… |
| CVE-2025-61648 | Ninguna (0) | 0.15% | — | 3 feb 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files… |
| CVE-2025-53479 | Media (5.4) | 0.18% | — | 8 jul 2025 | The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. This message is rendered without proper escaping, making it possible to inject JavaScript through… |
| CVE-2025-53480 | Media (5.4) | 0.18% | — | 8 jul 2025 | The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit this by… |
| CVE-2025-53478 | Media (5.4) | 0.18% | — | 7 jul 2025 | The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects… |
| CVE-2019-16529 | Media (5.3) | 0.87% | — | 19 mar 2020 | An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model. |
| CVE-2019-18611 | Media (6.5) | 0.93% | — | 29 oct 2019 | An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with… |
| CVE-2015-2940 | Media (6.8) | 1.1% | — | 13 abr 2015 | Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via… |