Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.
Remediation
References
Related Vulnerabilities
WordPress Plugin Art-Picture-Gallery Arbitrary File Upload (1.2.9)
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2019-19343)
Drupal Core 9.3.x Cross-Site Scripting (9.3.0 - 9.3.18)
WordPress Plugin WP eCommerce Cross-Site Scripting (3.9.2)
Liferay DXP Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2025-43810)