PatchSiren

The Wikimedia Foundation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM The Wikimedia Foundation CVE published 2026-07-01

CVE-2026-14363

CVE-2026-14363 is a SQL injection vulnerability in the Mediawiki - Cargo Extension. The issue affects Mediawiki - Cargo Extension versions before 1.43.9, 1.44.6, and 1.45.4. This vulnerability allows for SQL injection attacks, potentially leading to unauthorized data access or modification. Users should review the official CVE record and NVD details for accurate affected versions and upgrade guidance. The [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-07-01

CVE-2026-58517

The CVE record for CVE-2026-58517 was published on 2026-07-01T19:16:57.063Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This Improper Neutralization of Input Terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension could allow for authentication bypass, potentially impacting users of affected versions. Affected versions include Mediaw [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-07-01

CVE-2026-58520

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-01T18:16:35.983Z and has not been modified since then. The NVD entry is currently Analyzed. This open redirect vulnerability in Mediawiki - UrlShortener Extension allows Cross-Site Flashing and affects versions before 1.43.9, 1.44.6, 1.45.4. The vulnerability has a CVSS score of 6.9 and is classifie [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-07-01

CVE-2026-58518

CVE-2026-58518 is a Cross-Site request forgery (CSRF) vulnerability in Mediawiki - RedirectManager Extension. The issue affects Mediawiki - RedirectManager Extension from before 1.3.3. This vulnerability allows an attacker to perform unintended actions on behalf of a user. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. Users of Mediawiki - RedirectManager Extension before [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-04-07

CVE-2026-39936

CVE-2026-39936 is a cross-site scripting vulnerability in The Wikimedia Foundation Mediawiki - Score Extension. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. The vulnerability allows for Cross-Site Scripting (XSS) attacks due to improper neutralization of input during web page generation. Users of The Wikimedia Foundation Med [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-04-07

CVE-2026-39935

A cross-site scripting vulnerability was found in the Mediawiki - CampaignEvents Extension. The issue allows for Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation. This vulnerability was remediated on the `master` branch. Users should review the official advisory for affected scope and vendor guidance. The vulnerability has a CVSS score of 6.9 and is classified [truncated]

HIGH The Wikimedia Foundation CVE published 2026-04-07

CVE-2026-39937

CVE-2026-39937 is an Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension. This issue allows Resource Leak Exposure and has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. The vulnerability has a high CVSS score of 8.8, indicating a high severity. Def [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-04-07

CVE-2026-39934

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T22:16:24.137Z and has not been modified since then. CVE-2026-39934 is an infinite loop vulnerability in the Mediawiki - GrowthExperiments Extension. The issue allows for Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. The remediation was applied only on the `master` branch. Use [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-04-07

CVE-2026-39933

CVE-2026-39933 is a Cross-Site Scripting (XSS) vulnerability in the Mediawiki - GlobalWatchlist Extension. The issue allows for improper neutralization of input during web page generation, potentially leading to unauthorized script execution. Remediation has been applied on the `master` branch and in MediaWiki versions 1.43, 1.44, and 1.45. Users should review their installations for exposure and apply pa [truncated]

MEDIUM The Wikimedia Foundation CVE published 2026-04-07

CVE-2026-22711

The CVE record for CVE-2026-22711 was published on 2026-04-07T19:16:43.980Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The vulnerability affects The Wikimedia Foundation Mediawiki - Wikilove Extension, allowing Cross-Site Scripting (XSS) due to improper neutralization of alternate XSS syntax. The issue has been remediated in MediaWiki versions 1.43, 1.44, and 1.45. [truncated]