MediaWiki is a widely deployed wiki and content-management platform that powers numerous public and private knowledge bases, presenting a large attack surface despite a focused product footprint. Vulnerabilities affecting the vendor lean toward moderate severity outcomes and recur across the core platform and extensions such as CheckUser, Cargo, AbuseFilter, and VisualEditor through weakness classes centered on web-input handling, including cross-site scripting, cross-site request forgery, and improper data disclosure. The exposure pattern reflects the platform's role in rendering user-supplied and wiki-markup content across trust boundaries, making input neutralization and session management critical defense points. Defenders should maintain MediaWiki instances at current patch levels and apply security-focused configuration hardening, particularly where instances are internet-facing or handle sensitive knowledge domains; live severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mediawiki over time
Signals from CVEs in this vendor scope (463 CVEs).
463 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-1610MEDIUM MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary comma | Jan 30, 2014 | 6.0 | 65 | NO | YES |
CVE-2017-0372CRITICAL Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. | Apr 13, 2018 | 9.8 | 46 | NO | YES |
CVE-2026-14363CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
Th | Jul 1, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-58025CRITICAL Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/ | Jul 1, 2026 | 9.8 | 40 | NO | NO |
CVE-2022-29904CRITICAL The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. | Apr 29, 2022 | 9.8 | 39 | NO | NO |
CVE-2026-58521CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
Th | Jul 1, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-8857HIGH A vulnerability in Wikimedia Foundation timeline.
This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php.
This issue affects timeli | Jul 1, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-13706HIGH Improper input validation vulnerability in Wikimedia Foundation UrlShortener.
This vulnerability is associated with program files includes/UrlShortenerUtils.Php. | Jul 1, 2026 | 8.8 | 35 | NO | NO |
CVE-2025-67484CRITICAL Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php.
This issue affects MediaWiki: from * before 1.3 | Feb 3, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-13707HIGH Session fixation vulnerability in Wikimedia Foundation OAuth.
This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.
This issue affects OAuth: from | Jul 1, 2026 | 7.6 | 34 | NO | NO |
Signals from CVEs in this vendor scope (463 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mediawiki.
Media articles that mention a CVE ID that affects a product developed by Mediawiki — matched by CVE ID, not by vendor name.