CVE-2026-102796: Unauthenticated SQL injection in UserPageViewTracker via filterusers and ignoreusers parameters
Published Sep 29, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection.
This issue affects Mediawiki - UserPageViewTracker Extension: from before 1.46.1, 1.45.5, 1.43.10.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki UserPageViewTracker Extension<1.46.1, <1.45.5, <1.43.10
Event History
Sep 29, 2026
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionWeakness
Frequently Asked Questions
1
Which release lines need to be updated?
Affected releases are those before 1.46.1, 1.45.5, and 1.43.10 in their respective MediaWiki - UserPageViewTracker Extension release lines. These listed versions are the first unaffected releases.
2
Does exploitation require an authenticated account?
No. The issue is unauthenticated, so an attacker does not need to log in. Exploitation involves the filterusers and ignoreusers parameters.