10

CVSS3.1

CVE-2025-70841 -

Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database credentials, SMTP/SendGrid AP…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 3:58 p.m.

0

CVSS4.0

CVE-2025-61644 - i18n XSS through Special:Watchlist

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/WatchlistTopSectionWidget.Js. This issue affects MediaWiki: from * b…

πŸ“… Published: Feb. 2, 2026, 11:57 p.m. πŸ”„ Last Modified: April 15, 2026, 2:34 p.m.

0

CVSS4.0

CVE-2025-61637 - Stored XSS through system messages in MW Core

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Action/mediawiki.Action.Edit.Preview.Js, resources/src/mediawiki.Page.Preview.Js. …

πŸ“… Published: Feb. 2, 2026, 11:54 p.m. πŸ”„ Last Modified: March 16, 2026, 6:35 p.m.

0

CVSS4.0

CVE-2025-61638 - Sanitizer::validateAttributes data-XSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php. This issue affects M…

πŸ“… Published: Feb. 2, 2026, 11:52 p.m. πŸ”„ Last Modified: March 16, 2026, 6:34 p.m.

1.7

CVSS4.0

CVE-2025-61639 - Suppressed blocked IP is visible in Special:BlockList, RC, and other places

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/ManualLogEntry.Php, includes/recentchanges/RecentChangeFactory.Php, includes/recentchanges/RecentChangeStore.Php. This is…

πŸ“… Published: Feb. 2, 2026, 11:48 p.m. πŸ”„ Last Modified: March 16, 2026, 6:33 p.m.

0

CVSS4.0

CVE-2025-61640 - Stored XSS through system messages in Special:RecentChangesLinked (MW Core)

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/RclToOrFromWidget.Js. This issue affects MediaWiki: from * before 1.…

πŸ“… Published: Feb. 2, 2026, 11:42 p.m. πŸ”„ Last Modified: March 16, 2026, 6:32 p.m.

1.7

CVSS4.0

CVE-2025-61641 - API list=allpages with maxsize is making really slow queries

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

πŸ“… Published: Feb. 2, 2026, 11:39 p.m. πŸ”„ Last Modified: March 25, 2026, 2:01 p.m.

0

CVSS4.0

CVE-2025-61642 - Stored XSS through system messages provided to CodexHtmlForms

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects Med…

πŸ“… Published: Feb. 2, 2026, 11:36 p.m. πŸ”„ Last Modified: March 25, 2026, 2 p.m.

2.7

CVSS4.0

CVE-2025-61643 - EventStreams publishes suppressed recent change entries that are suppressed from their creation

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

πŸ“… Published: Feb. 2, 2026, 11:33 p.m. πŸ”„ Last Modified: March 25, 2026, 1:57 p.m.

0

CVSS4.0

CVE-2025-61634 - HTML rest endpoint needs PoolCounter and proper parser cache check

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

πŸ“… Published: Feb. 2, 2026, 11:28 p.m. πŸ”„ Last Modified: March 17, 2026, 3:22 p.m.
Total resulsts: 349182
Page 1852 of 34,919
Β« previous page Β» next page
Filters