Vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php.
This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
References
| Link | Resource |
|---|---|
| https://phabricator.wikimedia.org/T419192 | Vendor Advisory Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
13 May 2026, 22:30
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| References | () https://phabricator.wikimedia.org/T419192 - Vendor Advisory, Issue Tracking | |
| CPE | cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* | |
| First Time |
Mediawiki
Mediawiki mediawiki |
11 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-668 |
11 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 18:16
Updated : 2026-05-13 22:30
NVD link : CVE-2026-34095
Mitre link : CVE-2026-34095
CVE.ORG link : CVE-2026-34095
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE
CWE-668
Exposure of Resource to Wrong Sphere
