wikimedia foundation
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 194 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 13, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title
Blocked users can create and edit WikiLambda objects
Remote Code Execution via Unsafe Deserialization in LogItem Import
Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata
Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets
$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces
mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html
"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted
Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input
Users API leaks whether privileged users have their user groups disabled for lack of 2FA
Monitor wikimedia foundation in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.