This issue affects Mediawiki - EventBus Extension: 1.47.0-alpha.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: 1.47.0-alpha. | |
| Title | Private change tags exposed to anonymous users via revision-tags-change events | |
| Weaknesses | CWE-200 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2026-09-29T16:36:22.492Z
Reserved: 2026-09-25T16:02:34.842Z
Link: CVE-2026-100241
No data.
Status : Received
Published: 2026-09-29T17:17:01.113
Modified: 2026-09-29T17:17:01.113
Link: CVE-2026-100241
No data.
OpenCVE Enrichment
No data.
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor