CVE-2025-6590 – Complete content leak of private wikis due to PasswordReset Wikitext injection in error message

CVE ID : CVE-2025-6590

Published : Feb. 2, 2026, 11:03 p.m. | 13 minutes ago

Description : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLUserTextField.Php.

This issue affects MediaWiki: from * through 1.39.12, 1.42.76 1.43.1, 1.44.0.

Severity: 4.6 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه