SQL Injection Vulnerability in Wikimedia Foundation Mediawiki UserPageViewTracker Extension
CVE-2026-102796

Currently unrated

What is CVE-2026-102796?

The Mediawiki UserPageViewTracker Extension contains a vulnerability that allows for improper neutralization of special elements in SQL commands, potentially enabling an attacker to perform SQL injection attacks. This flaw impacts versions prior to 1.46.1, including 1.45.5 and 1.43.10. Exploiting this vulnerability could allow unauthorized commands or queries to be executed in the underlying database, leading to data exposure, corruption, or other malicious outcomes. It is crucial for users of the affected versions to apply the latest updates to mitigate the risk.

Affected Version(s)

Mediawiki - UserPageViewTracker Extension * < 1.46.1, 1.45.5, 1.43.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mjbommar
.