Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection.

This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Data Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unauthenticated SQL injection in the UserPageViewTracker extension of MediaWiki. Attackers can manipulate the filterusers and ignoreusers query parameters to inject arbitrary SQL code into backend queries, which can lead to extraction or modification of database contents. This flaw exposes sensitive data and can compromise the integrity of the system.

Affected Systems

The flaw impacts versions of the MediaWiki UserPageViewTracker extension that are earlier than 1.46.1, including 1.45.5 and 1.43.10, when distributed by the Wikimedia Foundation. Administrators running these legacy extensions are at risk.

Risk and Exploitability

No EPSS score is published and the vulnerability is not listed in the CISA KEV catalog. However, the combination of unauthenticated access and injection indicates that exploitation is technically feasible through simple web requests without special privileges. The absence of countermeasures in the affected code means the risk is moderate to high for applications exposed to the public internet.

Generated by OpenCVE AI on September 30, 2026 at 00:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the UserPageViewTracker extension to version 1.46.1 or later, which removes or sanitizes the vulnerable parameters.
  • If an upgrade cannot be performed immediately, block or delete the filterusers and ignoreusers query parameters by disabling the associated handler or configuring the web server to reject requests containing those parameters.
  • Apply input validation and use prepared statements for any remaining database interactions to prevent injection, following CWE-89 best practices.
  • Restrict access to the endpoint that processes these parameters so that only authenticated, privileged users can invoke it.

Generated by OpenCVE AI on September 30, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10.
Title Unauthenticated SQL injection in UserPageViewTracker via filterusers and ignoreusers parameters
Weaknesses CWE-89
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-29T16:55:37.825Z

Reserved: 2026-09-29T16:53:52.771Z

Link: CVE-2026-102796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T17:17:08.303

Modified: 2026-09-29T21:35:07.960

Link: CVE-2026-102796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')