PT-2026-54902 · Mediawiki · Mediawiki

CVE-2026-58033

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.46.0 MediaWiki versions prior to 1.45.4 MediaWiki versions prior to 1.44.6 MediaWiki versions prior to 1.43.9
Description Sensitive information may be exposed to unauthorized actors through the includes/Actions/InfoAction.Php file. Specifically, the total number of distinct authors statistic at the action=info endpoint fails to exclude revisions where the author name was deleted.
Recommendations Update to version 1.46.0 or later. Update to version 1.45.4 or later. Update to version 1.44.6 or later. Update to version 1.43.9 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58033

Affected Products

Mediawiki