CVE-2025-61646: Watchlist group mode reveals authors of edits with hidden authorship
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php.
This issue affects MediaWiki: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61646?
CVE-2025-61646 has a high severity as it reveals the authors of edits that were meant to be anonymous.
How do I fix CVE-2025-61646?
To fix CVE-2025-61646, update your MediaWiki installation to version 1.39.14 or later, or 1.43.4 or later, or 1.44.1.
What versions of MediaWiki are affected by CVE-2025-61646?
CVE-2025-61646 affects MediaWiki versions before 1.39.14, 1.43.4, and 1.44.1.
What components are involved in CVE-2025-61646?
CVE-2025-61646 specifically involves the includes/RecentChanges/EnhancedChangesList.php program file in MediaWiki.
Is there a workaround for CVE-2025-61646 while waiting for an update?
There are no recommended workarounds for CVE-2025-61646, so updating to a fixed version is necessary to mitigate the vulnerability.