High severity8.8NVD Advisory· Published Jul 3, 2025· Updated Jun 17, 2026
CVE-2025-53501
CVE-2025-53501
Description
Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2+ 1 more
- (no CPE)range: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2
- (no CPE)range: 1.39.x
Patches
Vulnerability mechanics
References
2- gerrit.wikimedia.org/r/c/mediawiki/extensions/Scribunto/+/1164541nvdPatch
- phabricator.wikimedia.org/T397524nvdExploitIssue TrackingPatch
News mentions
0No linked articles in our index yet.