Wikimedia's vulnerability footprint centers on a collection of web-facing tools and extensions that power collaborative editing and data querying across its open-knowledge projects, including Wikidata Query GUI, Parsoid, and analytics platforms. The recurring weakness classes reflect application-layer input-handling and access-control patterns—cross-site scripting, output-escaping issues, path traversal, and missing authorization checks—characteristic of complex server-side web software and extension ecosystems. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wikimedia over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47841HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue | Oct 5, 2024 | 7.5 | 38 | NO | NO |
CVE-2024-47845HIGH Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from | Oct 5, 2024 | 8.2 | 22 | NO | NO |
CVE-2018-25065MEDIUM A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic. This issue affects some unknown processing of the file I18nTags_body.php of the | Jan 5, 2023 | 6.1 | 22 | NO | NO |
CVE-2026-0671MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Si | Jan 8, 2026 | 6.1 | 21 | NO | NO |
CVE-2021-30458MEDIUM An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> t | Apr 9, 2021 | 6.1 | 20 | NO | NO |
CVE-2019-19329MEDIUM In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, | Nov 27, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-19327MEDIUM ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of results and number of milliseconds. NOTE | Nov 27, 2019 | 6.1 | 20 | NO | NO |
CVE-2026-22710MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Si | Jan 9, 2026 | 5.4 | 19 | NO | NO |
CVE-2020-36324MEDIUM Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type. | Apr 21, 2021 | 6.1 | 19 | NO | NO |
CVE-2019-19328MEDIUM ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE: this GUI code is no longer bu | Nov 27, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wikimedia.
Media articles that mention a CVE ID that affects a product developed by Wikimedia — matched by CVE ID, not by vendor name.