Improper Output Handling in ApprovedRevs Extension by Wikimedia Foundation
CVE-2026-22712
What is CVE-2026-22712?
The ApprovedRevs Extension for Mediawiki, developed by the Wikimedia Foundation, contains a vulnerability that allows for input data manipulation due to improper encoding or escaping of output. This flaw, resulting from a magic word replacement issue in the ParserAfterTidy function, can potentially enable malicious users to exploit the application, altering its intended behavior or revealing sensitive information. Affected versions include 1.45, 1.44, 1.43, and 1.39, emphasizing the need for immediate remediation to secure user data and maintain application integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mediawiki - ApprovedRevs Extension 1.45
Mediawiki - ApprovedRevs Extension 1.44
Mediawiki - ApprovedRevs Extension 1.43
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
