๐Ÿ” CVE Alert

CVE-2026-100241

UNKNOWN 0.0

Private change tags exposed to anonymous users via revision-tags-change events

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: 1.47.0-alpha.

CWE CWE-200
Vendor wikimedia foundation
Product mediawiki - eventbus extension
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for wikimedia foundation mediawiki - eventbus extension

Be the first to know when new unknown vulnerabilities affecting wikimedia foundation mediawiki - eventbus extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Wikimedia Foundation / Mediawiki - EventBus Extension
1.47.0-alpha

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T432948 gerrit.wikimedia.org: https://gerrit.wikimedia.org/r/q/I6d79037edc771fe9a2889c543e12cf7b1296aab8

Credits

kostajh