CVE-2025-32700: AbuseFilter log interfaces expose global private and hidden filters when central DB is not available
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseLog.Php, includes/Pager/AbuseLogPager.Php, includes/Special/SpecialAbuseLog.Php, includes/View/AbuseFilterViewExamine.Php.
This issue affects AbuseFilter: from >= 1.43.0 before 1.43.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32700?
CVE-2025-32700 is considered a high-severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2025-32700?
To fix CVE-2025-32700, upgrade the Wikimedia Foundation AbuseFilter to version 1.43.1 or later.
What kind of information is exposed in CVE-2025-32700?
CVE-2025-32700 may expose sensitive user data to unauthorized actors.
Which versions of AbuseFilter are affected by CVE-2025-32700?
CVE-2025-32700 affects Wikimedia Foundation AbuseFilter versions between 1.43.0 and 1.43.1.
Who is the vendor for CVE-2025-32700?
The vendor for CVE-2025-32700 is Wikimedia Foundation.