HTMLUserTextField exposes existence of hidden users (CVE-2022-41765).
reassignEdits doesn't update results in an IP range check on Special:Contributions (CVE-2022-41767)
{ "section": "core" }