CVE-2023-37253: Low severity MediaWiki ProofreadPage extension vulnerability
Published Sep 14, 2026
·Updated
An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.
Affected Software
1 affected component
MediaWiki ProofreadPage extension<=1.39.3
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Deployments using the ProofreadPage extension for MediaWiki are affected through version 1.39.3. The issue concerns information about suppressed users exposed through the API and configuration variables.
2
What access does an attacker need?
The CVSS vector indicates network access, low privileges, and no user interaction are required. Exploitation is rated high complexity.
3
What is the security impact?
The stated impact is limited to confidentiality: information about a suppressed user may be disclosed. No integrity or availability impact is identified.