Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
CVE-2026-58521: SQL Injection in Mediawiki Cargo Extension
CVE-2026-58521
Summary
A flaw in the Mediawiki Cargo Extension could allow hackers to inject malicious SQL code, potentially leading to unauthorized access to sensitive data. This affects users of the Cargo Extension in Mediawiki versions prior to 1.43.9, 1.44.6, and 1.45.4. To stay secure, update to the latest version of the Cargo Extension or install a patch if available.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mediawiki | cargo |
< 1.43.9 >= 1.44.0, < 1.44.6 >= 1.45.0, < 1.45.4 cpe:2.3:a:mediawiki:cargo:*:*:*:*:*:mediawiki:*:* |
Original title
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
This issue affects ...
Original description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.
This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.
nvd CVSS4.0
6.9
Vulnerability type
CWE-89
SQL Injection
Published: 1 Jul 2026 · Updated: 20 Jul 2026 · First seen: 1 Jul 2026