AbuseFilter
Wikimedia Foundation · 3 CVEs
CVE-2026-58027
MEDIUM
QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI
Jul 1, 2026
CVE-2026-34086
LOW
AbuseFilter misuses ::userCanBitfield, exposing access-controlled information
May 11, 2026
CVE-2025-6592
LOW
Creating a permanent account from a temporary account associates temp username and IP address with real username in Abu…
Feb 2, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-58027 | QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI | MEDIUM | 0.37% | Jul 1, 2026 |
| CVE-2026-34086 | AbuseFilter misuses ::userCanBitfield, exposing access-controlled information | LOW | 0.32% | May 11, 2026 |
| CVE-2025-6592 | Creating a permanent account from a temporary account associates temp username and IP address with real username in AbuseLog | LOW | 0.41% | Feb 2, 2026 |
Showing 1 to 3 of 3 CVEs