ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-34089
Vulnerability in Wikimedia Foundation Scribunto.

Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.

NVD description · AI analysis pending
2.3<1% PoC
  • wikimedia scribunto
CVE-2025-61638
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundatio

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoid: from * before 0.16.6, 0.20.4, 0.21.1.

NVD description · AI analysis pending
0.0<1%
  • mediawiki mediawiki
  • mediawiki parsoid
CVE-2026-0817
Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignE

Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39.

NVD description · AI analysis pending
5.3<1%
  • wikimedia campaignevents
CVE-2026-22710
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Exten

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Extension: 1.45, 1.44, 1.43, 1.39.

NVD description · AI analysis pending
2.3<1% PoC
  • wikimedia wikibase
CVE-2026-0671
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard exten

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39.

NVD description · AI analysis pending
6.1<1% PoC
  • wikimedia mediawiki-extensions-uploadwizard
CVE-2024-47841
+1 in the same advisory: …47845
Unauthenticated Path Traversal in Wikimedia MediaWiki CSS Extension

CVE-2024-47841 is a path traversal flaw (CWE-22) in the Wikimedia Foundation's CSS extension for MediaWiki, in which pathname input used by the extension's CSS-loading functionality is not properly restricted to the intended directory. An unauthenticated network attacker can supply crafted path components (e.g., ../ sequences) to make the extension reach and load files outside the allowed directory. Per the CVSS 4.0 score of 6.9, the impact is limited: low confidentiality (unintended local file disclosure) and low integrity (unintended content loaded as CSS), with no availability impact and no effect beyond the vulnerable component. Only MediaWiki deployments with the CSS extension installed on the 1.39.x, 1.41.x, or 1.42.x branches at the listed versions are affected. No confirmed in-the-wild exploitation is reported (not in CISA KEV), but a public PoC reference exists (Phabricator T369486) and the 34.6% EPSS score (98th percentile) signals a materially elevated probability of near-term exploitation.

Do: Sites running the CSS extension on MediaWiki 1.39.x, 1.41.x, or 1.42.x should upgrade to 1.39.9, 1.41.3, or 1.42.2 respectively (or later). If patching must be delayed, disable the CSS extension or restrict which users/requests can invoke it, and review access logs for path traversal patterns in CSS-related requests. The public PoC referenced in Phabricator task T369486 can be used to verify the fix.

6.935% PoC
  • wikimedia Mediawiki - CSS Extension 1.42.X before 1.42.2, 1.41.X before 1.41.3, and 1.39.X before 1.39.9
moderate≈ low thousands of wiki installations (estimate)
CVE-2024-47840
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allo

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.

NVD description · AI analysis pending
6.9<1% PoC
  • wikimedia apex
CVE-2018-25065
A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic.

A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic. This issue affects some unknown processing of the file I18nTags_body.php of the component Unlike Parser. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is b4bc3cbbb099eab50cf2b544cf577116f1867b94. It is recommended to apply a patch to fix this issue. The identifier VDB-217445 was assigned to this vulnerability.

NVD description · AI analysis pending
6.1<1%
  • wikimedia mediawiki-extensions-i18ntags
CVE-2020-36324
Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.

Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.

NVD description · AI analysis pending
6.1<1%
  • wikimedia analytics-quarry-web
CVE-2021-30458
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2.

An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a tag, bypassing sanitization steps, and potentially allowing for XSS.

NVD description · AI analysis pending
6.1<1%
  • wikimedia parsoid
CVE-2019-19329
+2 in the same advisory: …19328 …19327
In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript e

In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introducing MathJax as a new mathematics rendering engine. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.

NVD description · AI analysis pending
6.11% PoC
  • wikimedia wikidata query gui