Vulnerability in Wikimedia MediaWiki Affected by User Input Issues
CVE-2025-6593

2.1LOW

Key Information:

Status
Vendor
CVE Published:
2 February 2026

What is CVE-2025-6593?

A vulnerability exists in Wikimedia Foundation's MediaWiki, specifically concerning the handling of user input in the program file includes/user/User.php. This flaw affects multiple versions of MediaWiki, allowing different user-related operations to potentially be manipulated by malicious actors. The impacted versions include MediaWiki versions from 1.27.0 up to, but not including, 1.39.13, in addition to 1.42.7, 1.43.2, and 1.44.0. Addressing this issue is crucial to maintaining the integrity and security of MediaWiki installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MediaWiki 1.27.0 < 1.39.13, 1.42.7 1.43.2, 1.44.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.