MediaWiki vulnerabilities: known CVEs & security history
MediaWiki · Wiki · 405 tracked CVEs · 0 actively exploited · updated June 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all MediaWiki release lines — 405 in total. A CVE here doesn't mean your version is affected — check MediaWiki's current status and the safe version to run.
Known MediaWiki CVEs
Actively-exploited and most-severe first. Showing the top 80 of 405. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2025-67484 | critical | 9.8 | 0% | 2026 |
| CVE-2024-34502 | critical | 9.8 | 0% | 2024 |
| CVE-2023-37303 | critical | 9.8 | 1% | 2023 |
| CVE-2023-29141 | critical | 9.8 | 1% | 2023 |
| CVE-2022-29906 | critical | 9.8 | 1% | 2022 |
| CVE-2022-29904 | critical | 9.8 | 16% | 2022 |
| CVE-2022-28209 | critical | 9.8 | 1% | 2022 |
| CVE-2022-28206 | critical | 9.8 | 1% | 2022 |
| CVE-2022-28205 | critical | 9.8 | 1% | 2022 |
| CVE-2021-31556 | critical | 9.8 | 2% | 2021 |
| CVE-2021-36128 | critical | 9.8 | 1% | 2021 |
| CVE-2021-36126 | critical | 9.8 | 1% | 2021 |
| CVE-2020-10534 | critical | 9.8 | 1% | 2020 |
| CVE-2019-12468 | critical | 9.8 | 3% | 2019 |
| CVE-2017-0372 | critical | 9.8 | 12% | 2018 |
| CVE-2017-8809 | critical | 9.8 | 8% | 2017 |
| CVE-2014-9487 | critical | 9.8 | 2% | 2017 |
| CVE-2015-8009 | critical | 9.8 | 2% | 2017 |
| CVE-2015-8626 | critical | 9.8 | 2% | 2017 |
| CVE-2025-53501 | high | 8.8 | 0% | 2025 |
| CVE-2021-46147 | high | 8.8 | 1% | 2022 |
| CVE-2021-41801 | high | 8.8 | 1% | 2021 |
| CVE-2021-36132 | high | 8.8 | 1% | 2021 |
| CVE-2020-29004 | high | 8.8 | 1% | 2021 |
| CVE-2020-35626 | high | 8.8 | 1% | 2020 |
| CVE-2020-35625 | high | 8.8 | 1% | 2020 |
| CVE-2019-12466 | high | 8.8 | 1% | 2019 |
| CVE-2017-0367 | high | 8.8 | 2% | 2018 |
| CVE-2017-0362 | high | 8.8 | 1% | 2018 |
| CVE-2015-8624 | high | 8.8 | 1% | 2017 |
| CVE-2015-8623 | high | 8.8 | 1% | 2017 |
| CVE-2012-4381 | high | 8.1 | 4% | 2020 |
| CVE-2017-0361 | high | 7.8 | 0% | 2018 |
| CVE-2026-34092 | high | 7.5 | 0% | 2026 |
| CVE-2026-34091 | high | 7.5 | 0% | 2026 |
| CVE-2026-34088 | high | 7.5 | 0% | 2026 |
| CVE-2026-34087 | high | 7.5 | 0% | 2026 |
| CVE-2026-0669 | high | 7.5 | 0% | 2026 |
| CVE-2024-40597 | high | 7.5 | 0% | 2024 |
| CVE-2024-34506 | high | 7.5 | 1% | 2024 |
| CVE-2023-45371 | high | 7.5 | 1% | 2023 |
| CVE-2023-45363 | high | 7.5 | 23% | 2023 |
| CVE-2022-28204 | high | 7.5 | 1% | 2022 |
| CVE-2022-28203 | high | 7.5 | 1% | 2022 |
| CVE-2022-34750 | high | 7.5 | 1% | 2022 |
| CVE-2022-28323 | high | 7.5 | 1% | 2022 |
| CVE-2017-0371 | high | 7.5 | 2% | 2022 |
| CVE-2021-46149 | high | 7.5 | 1% | 2022 |
| CVE-2021-44858 | high | 7.5 | 1% | 2021 |
| CVE-2021-41799 | high | 7.5 | 2% | 2021 |
| CVE-2021-42040 | high | 7.5 | 1% | 2021 |
| CVE-2021-36125 | high | 7.5 | 1% | 2021 |
| CVE-2021-35197 | high | 7.5 | 2% | 2021 |
| CVE-2021-31555 | high | 7.5 | 1% | 2021 |
| CVE-2020-29005 | high | 7.5 | 1% | 2021 |
| CVE-2020-35623 | high | 7.5 | 1% | 2020 |
| CVE-2020-35475 | high | 7.5 | 2% | 2020 |
| CVE-2020-26121 | high | 7.5 | 1% | 2020 |
| CVE-2020-25869 | high | 7.5 | 1% | 2020 |
| CVE-2020-25827 | high | 7.5 | 2% | 2020 |
| CVE-2020-12051 | high | 7.5 | 1% | 2020 |
| CVE-2013-4572 | high | 7.5 | 2% | 2020 |
| CVE-2013-1817 | high | 7.5 | 3% | 2019 |
| CVE-2013-1816 | high | 7.5 | 3% | 2019 |
| CVE-2012-0046 | high | 7.5 | 1% | 2019 |
| CVE-2019-12474 | high | 7.5 | 2% | 2019 |
| CVE-2019-12473 | high | 7.5 | 2% | 2019 |
| CVE-2019-12472 | high | 7.5 | 1% | 2019 |
| CVE-2015-8008 | high | 7.5 | 3% | 2017 |
| CVE-2017-8815 | high | 7.5 | 2% | 2017 |
| CVE-2017-8814 | high | 7.5 | 2% | 2017 |
| CVE-2017-8810 | high | 7.5 | 2% | 2017 |
| CVE-2012-4380 | high | 7.5 | 2% | 2017 |
| CVE-2016-6337 | high | 7.5 | 1% | 2017 |
| CVE-2016-6335 | high | 7.5 | 2% | 2017 |
| CVE-2016-6332 | high | 7.5 | 2% | 2017 |
| CVE-2016-6331 | high | 7.5 | 2% | 2017 |
| CVE-2015-8625 | high | 7.5 | 2% | 2017 |
| CVE-2015-6728 | high | 7.5 | 1% | 2015 |
| CVE-2014-9277 | high | 7.5 | 2% | 2015 |
325 older / lower-severity CVEs not shown — see MediaWiki's full record.
Is my MediaWiki version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your MediaWiki version → · Monitor MediaWiki for new CVEs →
MediaWiki vulnerabilities — frequently asked
How many known vulnerabilities does MediaWiki have?
IsItPatched tracks 405 CVEs for MediaWiki. 19 are critical-severity and 74 high-severity. These span every release line — what matters is whether the version you run is affected.
Does MediaWiki have any actively-exploited vulnerabilities?
None of MediaWiki's tracked CVEs are currently in CISA's KEV catalog — but new ones can be added at any time, so keep your version current.
What is the most severe MediaWiki vulnerability?
Among tracked issues, CVE-2025-67484 (CRITICAL, CVSS 9.8) ranks highest — a Improper input validation weakness.
Is MediaWiki safe to use?
It depends on the version. The latest supported MediaWiki release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: MediaWiki security status · MediaWiki end-of-life · actively-exploited CVEs. Always verify against MediaWiki's advisories — see our disclaimer.