Vendor
MediaWiki is susceptible to an information disclosure flaw where the RESTBase-compatible API exposes the numeric user ID of hidden revision authors, allowing unauthenticated attackers to map IDs to usernames.