VendorsMediaWikicheckuserany version
Vulnerabilities

MediaWiki checkuser extension for Media wiki any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-67478
Wrong E-Mail address composition for usernames with a comma and Umlauts in it like "Döe, Jähn"
Published 2026-02-03 · Analyzed
8.8EPSS 0.003
CVE-2026-34090
Suggested investigations: Handle suppressed usernames
Published 2026-05-11 · Analyzed
7.5EPSS 0.004
CVE-2015-2940
Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.
Published 2015-04-13 · Modified
6.8EPSS 0.011
CVE-2019-18611
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with various levels of access to this extension. Said users should not have been able to view these oversighted edit summaries via the MediaWiki API.
Published 2019-10-29 · Modified
6.5EPSS 0.009
CVE-2025-61651
i18n XSS through Special:CheckUser CheckUser helper
Published 2026-02-03 · Analyzed
6.1EPSS 0.002
CVE-2025-61648
Stored XSS through system messages in CheckUser
Published 2026-02-03 · Analyzed
6.1EPSS 0.002
CVE-2019-16529
An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model.
Published 2020-03-19 · Modified
5.3EPSS 0.009
CVE-2025-61658
Special:GlobalContributions shows edits on wikis the viewer doesn't have access to
Published 2026-02-03 · Analyzed
4.3EPSS 0.002