Wikimedia Foundation / CheckUser
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-58034 | Stored XSS through a system message when blocking a temporary account that's related to other temporary accounts | MEDIUM | 4.8 | Jul 1, 2026 |
| CVE-2026-34090 | Suggested investigations: Handle suppressed usernames | MEDIUM | 4.8 | May 11, 2026 |
| CVE-2025-67478 | Wrong E-Mail address composition for usernames with a comma and Umlauts in it like "Döe, Jähn" | HIGH | 8.8 | Feb 3, 2026 |
| CVE-2025-61658 | Special:GlobalContributions shows edits on wikis the viewer doesn't have access to | LOW | 1.3 | Feb 3, 2026 |
| CVE-2025-61651 | i18n XSS through Special:CheckUser CheckUser helper | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2025-61648 | Stored XSS through system messages in CheckUser | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2025-61649 | UserInfoCard: Check that performing user has permission to view log entries for number of past blocks | LOW | 1.1 | Feb 3, 2026 |
| CVE-2025-61650 | UserInfoCard is vulnerable to message key stored XSS | LOW | 1.1 | Feb 3, 2026 |
| CVE-2025-61647 | UserInfoCard: Don't allow access to information about users who are suppressed if you don't have suppressor rights | LOW | 0.4 | Feb 3, 2026 |
Showing 1 to 9 of 9 CVEs