AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-35625

HIGH · CVSS 8.8 EPSS 1.03%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-35625
Severity
HIGH
CVSS
8.8
EPSS
1.03%

Original NVD Description

An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or MediaWiki) via a crafted HTML comment, related to a Smarty template. For example, a person in the Widget Editors group could use \MediaWiki\Shell\Shell::command within a comment.