Skip to main content

Daily materialized evidence profile

Vendor mediawiki

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
463
CVEs with mentions
65
Total mentions
91
CVEs with KEV
0
CVEs with PoC
2

Attack vector counts

Network
460
Adjacent network
0
Local
3
Physical
0

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2026-0668

Published Jan 7, 2026

Inefficient Regular Expression Complexity vulnerability in Wikimedia Foundation MediaWiki - VisualData Extension allows Regular Expression Exponential Blowup.This issue affects Me…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-14363

Published Jul 1, 2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. T…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-39839

Published Apr 7, 2026

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affect…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-11261

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with…

CVSS 0.0 · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2025-53489

Published Jul 3, 2025

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
21.0