CVE-2025-61635: Add rate limiting to ApiFancyCaptchaReload
Vulnerability in Wikimedia Foundation ConfirmEdit. This vulnerability is associated with program files includes/FancyCaptcha/ApiFancyCaptchaReload.Php.
This issue affects ConfirmEdit: .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61635?
CVE-2025-61635 is classified as a medium severity vulnerability due to its potential impact on application performance through excessive API usage.
How do I fix CVE-2025-61635?
To address CVE-2025-61635, implement rate limiting in the ApiFancyCaptchaReload function within the ConfirmEdit extension.
Who is affected by CVE-2025-61635?
Only users of the Wikimedia Foundation ConfirmEdit extension are affected by CVE-2025-61635.
What systems are vulnerable to CVE-2025-61635?
CVE-2025-61635 impacts systems running the Wikimedia Foundation ConfirmEdit extension that includes the FancyCaptcha feature.
When was CVE-2025-61635 disclosed?
CVE-2025-61635 was disclosed in 2025 and is an ongoing issue that needs to be mitigated by affected users.