Explore top 10 tips to secure your open-source projects now. Read More
×
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, code execution via unsafe deserialisation or cross-site scripting. For the stable distribution (trixie), these problems have been fixed in version 1:1.43.9+dfsg-1~deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6380-1
Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, which could lead to information disclosure or access controls bypass. CVE-2026-34087 OATHAuth extension: Users API leaks whether privileged users have. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4640-1
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6208-1
Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, which could lead to information disclosure, denial of service or privilege escalation. CVE-2025-67475 Square brackets in autocomment links were not always escaped.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4428-1
MGASA-2025-0260 - Updated mediawiki packages fix security vulnerabilities. MGASA-2025-0260 - Updated mediawiki packages fix security vulnerabilities Publication date: 05 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0260.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-3469, CVE-2025-32696, CVE-2025-32697, CVE-2025-32698, CVE-2025-32699, CVE-2025-32700, CVE-2025-32072, CVE-2025-11173, CVE-2025-11261, CVE-2025-61635, CVE-2025-61638, CVE-2025-61639, CVE-2025-61640, CVE-2025-61641, CVE-2025-61643, CVE-2025-61646, CVE-2025-61653 Description: i18n XSS vulnerability in HTMLMultiSelectField when sections are used. (CVE-2025-3469) "reupload-own" restriction can be bypassed by reverting file. (CVE-2025-32696) Cascading protection is not preventing file reversions. (CVE-2025-32697) LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions. (CVE-2025-32698) Potential javascript injection attack enabled by Unicode normalization in Action API. (CVE-2025-32699) AbuseFilter log interfaces expose global private and hidden filters when central DB is not available. (CVE-2025-32700) HTML injection in feed output from i18n message. (CVE-2025-32072) OATHAuth extension: Reauthentication for enabling 2FA can be bypassed by submitting a form in Special:OATHManage. (CVE-2025-11173) Stored i18n Cross-site scripting (XSS) vulnerability in mw.language.listToText. (CVE-2025-11261) ConfirmEdit extension: Missing rate limiting in ApiFancyCaptchaReload. (CVE-2025-61635) Parsoid: Validation bypass for `data-` attributes. (CVE-2025-61638) Log entries which are hidden from the creation of the entry may be disclosed to the public recent change entry. (CVE-2025-61639) Stored i18n Cross-site scripting (XSS) vulnerability in Special:RecentChangesLinked. (CVE-2025-61640) DDoS vulnerability in QueryAllPages API in miser mode. The `maxsize` value is now ignored in that mode. (CVE-2025-61641) Suppressed recentchanges may be disclosed to the public RCFeeds. (CVE-2025-61643) Public Watchlist/RecentChanges pages may disclose hidden usernames when an individual editor makes consecutive revisions on a single page, and only some are marked as hidden username. (CVE-2025-61646) TextExtracts extension: Information disclosure vulnerability in the extracts API action endpoint due to missing read permission check. (CVE-2025-61653) VisualEditor extension: Stored i18n Cross-site scripting (XSS) vulnerability in `lastModifiedAt` system messages. (CVE-2025-61655) VisualEditor extension: Missing attribute validation for attributes unwrapped from `data-ve-attributes`. (CVE-2025-61656) References: - https://bugs.mageia.org/show_bug.cgi?id=34211 - https://lists.debian.org/debian-security-announce/2025/msg00063.html - https://lists.wikimedia.org/hyperkitty/list/
Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure or privilege escalation. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4249-1
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting, information disclosure, HTML injection or incorrect tracking of authentication events. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5957-1
https://lists.wikimedia.org/hyperkitty/list/
Get the latest Linux and open source security news straight to your inbox.