🔐 CVE Alert

CVE-2025-67478

UNKNOWN 0.0

Wrong E-Mail address composition for usernames with a comma and Umlauts in it like "Döe, Jähn"

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php. This issue affects CheckUser: from * before 1.39.14, 1.43.4, 1.44.1.

Vendor wikimedia foundation
Product checkuser
Published Feb 3, 2026
Last Updated Mar 2, 2026
Stay Ahead of the Next One

Get instant alerts for wikimedia foundation checkuser

Be the first to know when new unknown vulnerabilities affecting wikimedia foundation checkuser are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Wikimedia Foundation / CheckUser
* < 1.39.14, 1.43.4, 1.44.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T385403