Sensitive Information Exposure in MediaWiki PageTriage by Wikimedia Foundation
CVE-2026-103440

1.2LOW

What is CVE-2026-103440?

A vulnerability in the MediaWiki PageTriage extension enables the exposure of sensitive information through improper data queries. Attackers can potentially elicit data that should be protected, impacting user privacy and system integrity. This issue affects specific versions of the PageTriage extension, prompting the need for immediate attention and remedial actions to safeguard sensitive information.

Affected Version(s)

MediaWiki PageTriage extension 1.46

MediaWiki PageTriage extension 1.45

MediaWiki PageTriage extension 1.43

References

CVSS V4

Score:
1.2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
.