CVE-2025-67480: list=allrevisions can be used to bypass Extension:Lockdown
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php.
This issue affects MediaWiki: from before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67480?
CVE-2025-67480 is classified as a medium severity vulnerability that allows bypassing security measures in MediaWiki.
How do I fix CVE-2025-67480?
To fix CVE-2025-67480, upgrade to MediaWiki version 1.39.16 or later, or any of the secure versions if currently using 1.43.6, 1.44.3, or 1.45.1.
What versions of MediaWiki are affected by CVE-2025-67480?
CVE-2025-67480 affects MediaWiki versions prior to 1.39.16, and the specific versions 1.43.6, 1.44.3, and 1.45.1.
Can CVE-2025-67480 lead to data exposure?
Yes, CVE-2025-67480 can lead to unauthorized access and data exposure by bypassing the Extension:Lockdown restrictions.
Is there a patch available for CVE-2025-67480?
A patch is included in the latest MediaWiki releases following the identified vulnerable versions.