CVE-2025-6590 – Complete content leak of private wikis due to PasswordReset Wikitext injection in error message
CVE ID : CVE-2025-6590
Published : Feb. 2, 2026, 11:03 p.m. | 13 minutes ago
Description : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLUserTextField.Php.
This issue affects MediaWiki: from * through 1.39.12, 1.42.76 1.43.1, 1.44.0.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…