Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
{
"versions": [
{
"introduced": "1.23.0"
},
{
"last_affected": "1.23.16"
},
{
"introduced": "1.27.0"
},
{
"fixed": "1.27.2"
},
{
"introduced": "1.28.0"
},
{
"fixed": "1.28.1"
}
]
}