Vulnerabilidades em Wikimedia Foundation

136 resultados
Análise Vexday

Com 118 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco da Wikimedia Foundation situa-se abaixo da média geral do catálogo, o que sugere baixa pressão de ameaças imediatas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web de grande escala e que requer atenção contínua em processos de sanitização de entrada. As 3 CVEs de severidade crítica e as 17 surgidas nos últimos 90 dias indicam uma superfície em expansão moderada que merece acompanhamento. A CVE mais perigosa atualmente apontada é CVE-2013-4572, com escore EPSS de 0,0214, valor baixo que, somado à ausência de PoCs públicas conhecidas, não sinaliza risco de exploração elevado no curto prazo, mas a antiguidade da vulnerabilidade pode indicar débito técnico pendente de correção.

CVE-2025-6926HIGHSecurity Authentication Bypass in CentralAuthEPSS 0.4%CVE-2025-32700LOWAbuseFilter log interfaces expose global private and hidden filters when central DB is not availableEPSS 0.4%CVE-2025-32697NONECascading protection is not preventing file reversionsEPSS 0.4%CVE-2025-6592LOWCreating a permanent account from a temporary account associates temp username and IP address with real username in AbuseLogEPSS 0.4%CVE-2025-32699LOWPotential javascript injection attack enabled by Unicode normalization in Action APIEPSS 0.4%CVE-2025-61635NONEAdd rate limiting to ApiFancyCaptchaReloadEPSS 0.4%CVE-2025-11173NONEReauth for enabling 2FA can be bypassed by submitting a formEPSS 0.4%CVE-2025-23074LOWSpecial:EditProfile exposes the contents of profile fields marked "hidden"/friends or "friends of friends" when the privileged user isn't a friend of the user whose profile they edit(ed)EPSS 0.3%CVE-2025-23073LOWAPI list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameterEPSS 0.3%CVE-2025-61653LOWExtension:TextExtracts does not check for authorizeRead when returning extractsEPSS 0.3%CVE-2026-13706NONEUrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWGEPSS 0.3%CVE-2026-58025MEDIUMRemote Code Execution via Unsafe Deserialization in LogItem ImportEPSS 0.3%CVE-2025-6590MEDIUMComplete content leak of private wikis due to PasswordReset Wikitext injection in error messageEPSS 0.3%CVE-2025-32696NONE"reupload-own" restriction can be bypassed by reverting fileEPSS 0.3%CVE-2025-61649LOWUserInfoCard: Check that performing user has permission to view log entries for number of past blocksEPSS 0.3%CVE-2025-53501HIGHContent Access Bypass in ScribuntoEPSS 0.3%CVE-2025-61654NONEUserInfoCard: Do permission checking when getting counts of global and local edits, new articles and thanksEPSS 0.3%CVE-2025-67478NONEWrong E-Mail address composition for usernames with a comma and Umlauts in it like "Döe, Jähn"EPSS 0.3%CVE-2025-23072MEDIUMXSS in Special:RefreshSpecialEPSS 0.3%CVE-2025-23080MEDIUMXSSes in Special:BadgeViewEPSS 0.3%