CVE-2026-58521 is a SQL injection vulnerability in Mediawiki - Cargo Extension. The issue affects Mediawiki - Cargo Extension versions before 1.43.9, 1.44.6, and 1.45.4. This vulnerability allows for SQL injection attacks due to improper neutralization of special elements used in an SQL command. Users of Mediawiki - Cargo Extension should review their installations and update to a patched version if neces [truncated]
CVE-2026-34094 is a low-severity MediaWiki vulnerability affecting specific release branches before 1.43.7, 1.44.4, and 1.45.2. The NVD record points to Wikimedia’s Phabricator issue T416090 as the vendor advisory/patch reference. Based on the published CVSS v4.0 vector, exploitation is network-reachable but requires high privileges and some user interaction, with limited confidentiality impact and no lis [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T20:16:33.773Z and has not been modified since then. The vulnerability affects Mediawiki - Cargo Extension before version 3.8.7, allowing Stored XSS attacks due to improper neutralization of Script-Related HTML tags in a web page (basic XSS). Users of Mediawiki - Cargo Extension should apply patch [truncated]
CVE-2026-39837 is a basic XSS vulnerability in Mediawiki - Cargo Extension before 3.8.7 due to improper neutralization of Script-Related HTML tags. This allows for Stored XSS attacks. The issue affects Mediawiki - Cargo Extension versions before 3.8.7. Users of affected versions should apply patches or updates to prevent XSS attacks. The vulnerability has a CVSS score of 6.3 and is considered Medium priority.