CVE-2023-37253: Mediawiki Proofreadpage
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.
Affected products
- Mediawiki Proofreadpage: before 1.35.11 (fixed in 1.35.11); from 1.36.0, before 1.38.7 (fixed in 1.38.7); from 1.39.0, before 1.39.4 (fixed in 1.39.4)
Published 2026-09-14. Last modified 2026-09-16.