Wikisource maintains a narrowly scoped vulnerability footprint centered on the ProofreadPage extension for its collaborative digital library and document transcription platform. The observed exposure centers on input-handling issues in web-page generation, particularly cross-site scripting vulnerabilities that can arise in user-facing text-processing and editing contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wikisource over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0670MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage Extension allows Cross-S | Jan 7, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wikisource.
Media articles that mention a CVE ID that affects a product developed by Wikisource — matched by CVE ID, not by vendor name.