MediaWiki < 1.39.14 Multiple Vulnerabilities

high Web App Scanning Plugin ID 115335

Synopsis

MediaWiki < 1.39.14 Multiple Vulnerabilities

Description

According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.14, 1.43.x prior to 1.43.4 or 1.44.x prior to 1.44.1. It is, therefore, affected by a number of vulnerabilities as follows.

- REST does not set a cache-control value of max-age=60 for redirects. (CVE-2025-61634)

- ApiFancyCaptchaReload does not reuse the badcaptcha rate limit in ConfirmEdit. (CVE-2025-61635)

- Failure to escape rawElement $content. (CVE-2025-61636)

- Failure to escape three system messages used by live preview. (CVE-2025-61637)

- Failure to sanitize data- attributes (also affects Parsoid). (CVE-2025-61638)

- Improper use of ManualLogEntry::getDeleted in ::getRecentChange. (CVE-2025-61639)

- Messages are inserted as HTML instead of being parsed. (CVE-2025-61640)

- maxsize is not disabled in QueryAllPages in miser mode. (CVE-2025-61641)

- Failure to escape the submit button label for Codex-based HTMLForms. (CVE-2025-61642)

- Suppressed recent changes are sent to RCFeeds. (CVE-2025-61643)

- i18n XSS in CodexTablePager. (CVE-2025-61645)

- Hidden usernames are leaked in Watchlist/RecentChanges. (CVE-2025-61646)

- Failure to escape system messages before inserting them as HTML in CheckUser. (CVE-2025-61648)

- XSS in the tempuser-expired-link-tooltip message in CheckUser. (CVE-2025-61651)

- API does not check user read permissions before showing PageInfo in DiscussionTools. (CVE-2025-61652)

- Missing authorizeRead check for the extracts endpoint in TextExtracts. (CVE-2025-61653)

- Deleted entries are not excluded when counting thanks in Thanks. (CVE-2025-61654)

- Improper escaping and parsing of system messages in VisualEditor. (CVE-2025-61655)

- Failure to sanitize attributes unwrapped from data-ve-attributes in VisualEditor. (CVE-2025-61656)

- Sticky header labels are inserted as HTML instead of text in Vector. (CVE-2025-61657)

- Missing config variable to exclude from GlobalContributions in CheckUser. (CVE-2025-61658)

- Reauth for enabling 2FA can be bypassed by submitting a form in OATHAuth. (CVE-2025-11173)

- DiscussionTools uses an insufficient regex. (CVE-2025-11175)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to MediaWiki version 1.39.14 or later.

See Also

https://lists.wikimedia.org/hyperkitty/list/[email protected]/thread/6I6GV6OP27OB7CZS2JUQ5IC6XFXRHLNQ/

Plugin Details

Severity: High

ID: 115335

Type: Version Based

Published: 7/28/2026

Updated: 7/28/2026

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.41

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:C

CVSS Score Source: CVE-2025-11175

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2025-11175

CVSS v4

Risk Factor: High

Base Score: 8.8

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N

CVSS Score Source: CVE-2025-11175

Vulnerability Information

CPE: cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/30/2025

Reference Information

CVE: CVE-2025-11173, CVE-2025-11175, CVE-2025-61634, CVE-2025-61635, CVE-2025-61636, CVE-2025-61637, CVE-2025-61638, CVE-2025-61639, CVE-2025-61640, CVE-2025-61641, CVE-2025-61642, CVE-2025-61643, CVE-2025-61645, CVE-2025-61646, CVE-2025-61648, CVE-2025-61651, CVE-2025-61652, CVE-2025-61653, CVE-2025-61654, CVE-2025-61655, CVE-2025-61656, CVE-2025-61657, CVE-2025-61658

CWE: 20, 200, 212, 22, 287, 79, 917

OWASP: 2010-A1, 2010-A2, 2010-A3, 2010-A4, 2010-A6, 2013-A1, 2013-A2, 2013-A3, 2013-A4, 2013-A5, 2013-A9, 2017-A1, 2017-A2, 2017-A5, 2017-A6, 2017-A7, 2017-A9, 2021-A1, 2021-A3, 2021-A6, 2021-A7, 2025-A1, 2025-A5, 2025-A6, 2025-A7

WASC: Cross-Site Scripting, Improper Input Handling, Information Leakage, Insufficient Authentication, Path Traversal

CAPEC: 10, 101, 104, 108, 109, 110, 114, 115, 116, 120, 126, 13, 135, 136, 14, 151, 153, 169, 182, 194, 209, 22, 224, 23, 230, 231, 24, 250, 261, 267, 273, 28, 285, 287, 290, 291, 292, 293, 294, 295, 296, 297, 298, 299, 3, 300, 301, 302, 303, 304, 305, 306, 307, 308, 309, 31, 310, 312, 313, 317, 318, 319, 320, 321, 322, 323, 324, 325, 326, 327, 328, 329, 330, 34, 42, 43, 45, 46, 47, 472, 473, 497, 508, 51, 52, 53, 57, 573, 574, 575, 576, 577, 588, 59, 591, 592, 593, 6, 60, 616, 63, 633, 64, 643, 646, 650, 651, 67, 7, 71, 72, 73, 76, 78, 79, 8, 80, 81, 83, 84, 85, 88, 9, 94

DISA STIG: APSC-DV-000460, APSC-DV-002490, APSC-DV-002560, APSC-DV-002630

HIPAA: 164.306(a)(1), 164.306(a)(2), 164.312(a)(1), 164.312(a)(2)(i)

ISO: 27001-A.13.1.1, 27001-A.14.1.2, 27001-A.14.1.3, 27001-A.14.2.5, 27001-A.18.1.3, 27001-A.6.2.2, 27001-A.9.1.2, 27001-A.9.4.1, 27001-A.9.4.4, 27001-A.9.4.5

NIST: sp800_53-AC-3, sp800_53-CM-6b, sp800_53-SI-10, sp800_53-SI-15

OWASP API: 2019-API7, 2019-API8, 2023-API8

OWASP ASVS: 4.0.2-12.3.1, 4.0.2-14.2.1, 4.0.2-5.1.3, 4.0.2-5.2.5, 4.0.2-5.3.3, 4.0.2-8.3.4

PCI-DSS: 3.2-6.2, 3.2-6.5, 3.2-6.5.1, 3.2-6.5.10, 3.2-6.5.7, 3.2-6.5.8