Citizen
Vendor:
First CVE: Jun 3, 2024 · Active for 2 years
9
Total CVEs
More Total CVEs than 88% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 13% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Citizen over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2024
2 years ago
Most Recent CVE
Jul 3, 2025
390 days ago
CVE Severity & Scoring
Citizen9 CVEs
100%
All CVEs353,240 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required9 (100.0%)
Privileges Required
Low8 (88.9%)
High1 (11.1%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-53370MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription extension ar | Jul 3, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-53368MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper | Jul 3, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-49576MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted | Jun 12, 2025 | 5.4 | 17 | NO | NO |
CVE-2025-49575MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody | Jun 12, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-47536MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves | Sep 30, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-36123MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascrip | Jun 3, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-49579MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, a | Jun 12, 2025 | 4.8 | 16 | NO | NO |
CVE-2025-49578MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybo | Jun 12, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-49577MEDIUM Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those mess | Jun 12, 2025 | 5.4 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Citizen
Top CWEs
Versions
No cataloged versions.