CVE-2023-45374: Mediawiki

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.

Affected products

  • Mediawiki Mediawiki: before 1.35.12 (fixed in 1.35.12); from 1.36.0, before 1.39.5 (fixed in 1.39.5); version 1.40.0 only

Published 2023-10-09. Last modified 2026-06-17.