Product
MediaWiki is vulnerable to remote code execution (CVE-2026-58025) via insecure PHP deserialization within the LogEntryBase::extractParams method, allowing authenticated sysop users to execute arbitrary code through malicious XML imports.